Stack-based buffer overflow in expat - CVE-2024-8176

 

Stack-based buffer overflow in expat - CVE-2024-8176

Published: March 14, 2025 / Updated: July 7, 2025


Vulnerability identifier: #VU105723
CSH Severity: High
CVSS v4 BT: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2024-8176
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when handling XML content. A remote attacker can pass specially crafted XML content to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

expat
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
visionOS
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
OpenBSD
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
watchOS
macOS
Slackware Linux
Basesystem Module
openSUSE Leap
iPadOS
tvOS
Apple iOS
openEuler
Ubuntu
Fedora
IBM Concert Software
IBM Observability with Instana
Netcool Operations Insight
IBM OmniFind Text Search Server for DB2 for i
Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition
Oracle Financial Services Behavior Detection Platform
Tenable Nessus
IBM Security Verify Governance
IBM Power Hardware Management Console (HMC)
Oracle HTTP Server
IBM Automation Decision Services
Submariner
Service Interconnect
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
App Connect Enterprise Certified Container
Rapid Infrastructure Automation
IBM Cloud Pak for Watson AIOps
IBM Enterprise Content Management Text Search
IBM Engineering Requirements Management DOORS Next
Verify Identity Access Digital Credentials
APEX Cloud Platform for Microsoft Azure
System Storage DS8900F
Nessus Network Monitor
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Communications Unified Assurance
LANTIME Operating System Firmware (LTOS)
IBM Qradar SIEM
Oracle Outside In Technology
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
xmlrpc-c (Red Hat package)
xmlrpc-c
xmlrpc-c-doc
xmlrpc-c-c++
xmlrpc-c-client++
xmlrpc-c-devel
xmlrpc-c-client
xmlrpc-c-apps
expat-devel
expat
expat-debuginfo
expat-debugsource
expat-help
expat (Red Hat package)
expat (Ubuntu package)
libexpat1 (Ubuntu package)
expat-doc
expat-static
libexpat-devel
libexpat1-debuginfo-32bit
expat-debuginfo-32bit
libexpat1-32bit
libexpat1-debuginfo
libexpat1
expat-32bit-debuginfo
libexpat1-32bit-debuginfo
expat-64bit-debuginfo
libexpat1-64bit-debuginfo
libexpat1-64bit
libexpat-devel-64bit
libexpat-devel-32bit
IBM Security Verify Access
IBM DS8000 Hardware Management Console
IBM API Connect
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
SmartFabric Manager
Red Hat OpenShift GitOps
IBM FileNet Content Manager
Red Hat Ceph Storage

How to mitigate CVE-2024-8176

Install updates from vendor's website.

expat - update to 2.7.0
IBM Concert Software - update to 2.0.0
visionOS - update to 2.5
IBM Observability with Instana - update to 1.0.297
Rapid Infrastructure Automation - update to 1.1.5.3
Netcool Operations Insight - update to 1.6.15
IBM Cloud Pak for Watson AIOps - update to 4.10.0
Nessus Network Monitor - addressed in versions 6.5.1, 6.5.3
LANTIME Operating System Firmware (LTOS) - update to 7.08.023
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
watchOS - update to 11.5
Tenable Nessus - addressed in versions 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1
IBM Security Verify Governance - update to 10.0.2.0.7
IBM API Connect - update to 10.0.8.5
IBM Power Hardware Management Console (HMC) - update to 10.3.1060.0 SP2
macOS - addressed in versions 13.7.6 22H625, 14.7.6 23H626, 15.5 24F74
iPadOS - addressed in versions 17.7.7, 18.5 22F76
tvOS - update to 18.5
Apple iOS - update to 18.5 22F76
Submariner - addressed in versions 0.18.5, 0.19.4, 0.20.1
Red Hat OpenShift Serverless - update to 1
Service Interconnect - addressed in versions 1, 1.4
SmartFabric Manager - update to 1.3.0
Multicluster GlobalHub - update to 1.4.1
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
Migration Toolkit for Containers - update to 1.8.7
Red Hat OpenShift GitOps - addressed in versions 1.15.3, 1.16.1
xmlrpc-c (Red Hat package) - addressed in versions 1.51.0-5.el8_2.2, 1.51.0-5.el8_4.2, 1.51.0-6.el8_6.1
xmlrpc-c - addressed in versions 1.51.0-11.0.1, 1.54.05-3
xmlrpc-c-doc - addressed in versions 1.51.0-11.0.1, 1.54.05-3
xmlrpc-c-c++ - addressed in versions 1.51.0-11.0.1, 1.54.05-3
xmlrpc-c-client++ - addressed in versions 1.51.0-11.0.1, 1.54.05-3
xmlrpc-c-devel - addressed in versions 1.51.0-11.0.1, 1.54.05-3
xmlrpc-c-client - addressed in versions 1.51.0-11.0.1, 1.54.05-3
xmlrpc-c-apps - update to 1.54.05-3
expat-devel - addressed in versions 2.2.5-17, 2.5.0-5
expat - addressed in versions 2.2.5-17, 2.5.0-5
expat - addressed in versions 2.2.9-19, 2.4.1-19, 2.5.0-12
expat-debuginfo - addressed in versions 2.2.9-19, 2.4.1-19, 2.5.0-12
expat-debugsource - addressed in versions 2.2.9-19, 2.4.1-19, 2.5.0-12
expat-devel - addressed in versions 2.2.9-19, 2.4.1-19, 2.5.0-12
expat-help - addressed in versions 2.2.9-19, 2.4.1-19, 2.5.0-12
expat (Red Hat package) - addressed in versions 2.2.10-1.el8_4, 2.2.10-1.el8_6, 2.2.10-1.el8_8, 2.2.10-12.el9_0.4, 2.5.0-1.el9_2.3, 2.5.0-3.el9_5.3, 2.5.0-5.el9_6
expat (Ubuntu package) - addressed in versions 2.4.7-1ubuntu0.6, 2.6.1-2ubuntu0.3, 2.6.2-2ubuntu0.2
libexpat1 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu0.6, 2.6.1-2ubuntu0.3, 2.6.2-2ubuntu0.2
Multicluster Engine for Kubernetes - addressed in versions 2.4.9, 2.5.9, 2.6.7, 2.6.8, 2.7.4, 2.8.1
expat-doc - update to 2.5.0-5
expat-static - update to 2.5.0-5
expat - update to 2.7.0
expat - addressed in versions 2.7.0-1.fc40, 2.7.0-1.fc41
expat-debugsource - addressed in versions 2.7.1-21.43.1, 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
libexpat-devel - addressed in versions 2.7.1-21.43.1, 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
expat - addressed in versions 2.7.1-21.43.1, 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
libexpat1-debuginfo-32bit - update to 2.7.1-21.43.1
expat-debuginfo-32bit - update to 2.7.1-21.43.1
libexpat1-32bit - addressed in versions 2.7.1-21.43.1, 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
libexpat1-debuginfo - addressed in versions 2.7.1-21.43.1, 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
libexpat1 - addressed in versions 2.7.1-21.43.1, 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
expat-debuginfo - addressed in versions 2.7.1-21.43.1, 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
expat-32bit-debuginfo - addressed in versions 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
libexpat1-32bit-debuginfo - addressed in versions 2.7.1-150000.3.36.1, 2.7.1-150400.3.28.1, 2.7.1-150700.3.3.1
expat-64bit-debuginfo - update to 2.7.1-150400.3.28.1
libexpat1-64bit-debuginfo - update to 2.7.1-150400.3.28.1
libexpat1-64bit - update to 2.7.1-150400.3.28.1
libexpat-devel-64bit - update to 2.7.1-150400.3.28.1
libexpat-devel-32bit - update to 2.7.1-150400.3.28.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.9, 2.10.8, 2.11.7, 2.12.3, 2.13.2, 2.13.3
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Dev Spaces - addressed in versions 3.20.0, 3.21.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14, 4.17.7
Red Hat OpenShift Container Platform - addressed in versions 4.13.58, 4.14.51, 4.15.50
OpenShift Virtualization - addressed in versions 4.16.7, 4.19.17
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.3
IBM FileNet Content Manager - addressed in versions 5.5.12.0 IF007, 5.6.0.0 IF006, 5.7.0.0 IF003
OpenShift Logging - addressed in versions 5.8.20, 5.9.13
Red Hat Ceph Storage - addressed in versions 6.1, 8.1
IBM DS8000 Hardware Management Console - update to 10.10.106.0 R10.1
App Connect Enterprise Certified Container - addressed in versions 12.0.11, 12.11.0
System Storage DS8900F - update to 89.44.4.0 R9.4 SP4

External References

Related Security Bulletins