Buffer Underwrite ('Buffer Underflow') in expat - CVE-2024-45490
Published: September 5, 2024 / Updated: May 20, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in xmlparse.c when handling negative length for XML_ParseBuffer. A remote attacker can pass specially crafted input to the application, trigger buffer underflow and execute arbitrary code on the system.
Affected software
Debian Linux
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
visionOS
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
IBM AIX
OpenBSD
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
watchOS
macOS
Ubuntu
Slackware Linux
Desktop Applications Module
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
tvOS
iPadOS
Apple iOS
openEuler
Fedora
IBM Concert Software
Cryostat
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Security Verify Governance
IBM Netezza Analytics for NPS
Service Interconnect
Data Lakehouse
IBM MQ Operator
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
App Connect Enterprise Certified Container
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
IBM Observability with Instana
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
Precision 7920 Rack
Precision 7920 XL Rack
PowerScale OneFS
JBoss Core Services
IBM VIOS
IBM OpenPages with Watson
IBM Engineering Requirements Management DOORS Next
Cloud Pak for Network Automation
OpenManage Network Integration (OMNI)
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
watsonx Assistant for IBM Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
IBM Business Automation Manager Open Editions
Juniper Junos Space
libxmltok1t64 (Ubuntu package)
lib64expat1 (Ubuntu package)
libexpat1 (Ubuntu package)
expat (Ubuntu package)
libxmltok1 (Ubuntu package)
xmlrpc-c-debuginfo
xmlrpc-c
xmlrpc-c-help
xmlrpc-c-devel
xmlrpc-c-debugsource
libexpat1-debuginfo-32bit
expat-debugsource
libexpat-devel
expat-debuginfo
libexpat1-debuginfo
expat-debuginfo-32bit
libexpat1-32bit
expat
libexpat1
expat-devel
expat (Red Hat package)
expat-help
libexpat1-64bit-debuginfo
expat-64bit-debuginfo
libexpat-devel-64bit
expat-32bit-debuginfo
libexpat-devel-32bit
libexpat1-32bit-debuginfo
libexpat1-64bit
expat (Debian package)
expat-static
expat-doc
mingw-expat
python3.8
python3
python3.9
python3.10
mozjs52-debuginfo
libmozjs-52
mozjs52
libmozjs-52-debuginfo
mozjs52-debugsource
mozjs52-devel
libmozjs-60-debuginfo
mozjs60-devel
mozjs60-debuginfo
mozjs60
libmozjs-60
mozjs60-debugsource
libmozjs-78-0-debuginfo
libmozjs-78-0
mozjs78-debuginfo
mozjs78
mozjs78-debugsource
mozjs78-devel
dev-qt/qtwebengine
mozjs115-debuginfo
mozjs115-devel
libmozjs-115-0-debuginfo
mozjs115
libmozjs-115-0
mozjs115-debugsource
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
IBM Cloud Pak System
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
iDRAC9
IBM Qradar SIEM
NetWorker Management Console
How to mitigate CVE-2024-45490
IBM Concert Software - update to 1.0.3
visionOS - update to 2.2
SmartFabric Storage Software - update to 1.4.3
JBoss Core Services - update to 2.4.62
LANTIME Operating System Firmware (LTOS) - update to 7.08.016
IBM OpenPages with Watson - update to 9.1.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
watchOS - update to 11.2
IBM Security Verify Governance - update to 10.0.2.0.5
IBM Netezza Analytics for NPS - update to 11.2.30
macOS - addressed in versions 13.7.2 22H308, 14.7.2 23H304, 15.2 24C101
tvOS - update to 18.2
iPadOS - addressed in versions 17.7.3, 18.2 22C152
Apple iOS - update to 18.2 22C152
Juniper Junos Space - update to 24.1R2
libxmltok1t64 (Ubuntu package) - update to Ubuntu Pro
lib64expat1 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libexpat1 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.2.9-1ubuntu0.7, 2.4.7-1ubuntu0.4, 2.6.1-2ubuntu0.1
expat (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.2.9-1ubuntu0.7, 2.4.7-1ubuntu0.4, 2.6.1-2ubuntu0.1
libxmltok1 (Ubuntu package) - update to Ubuntu Pro
Service Interconnect - addressed in versions 1, 1.4
Data Lakehouse - update to 1.3.0.0
Red Hat OpenShift GitOps - addressed in versions 1.12.6, 1.13.2
xmlrpc-c-debuginfo - update to 1.51.08-3
xmlrpc-c - update to 1.51.08-3
xmlrpc-c-help - update to 1.51.08-3
xmlrpc-c-devel - update to 1.51.08-3
xmlrpc-c-debugsource - update to 1.51.08-3
xmlrpc-c - addressed in versions 1.60.04-1.fc42, 1.60.04-2.fc42
IBM MQ Operator - addressed in versions 2.0.28, 3.2.6, 3.3.0, 9.4.1.0-r1
libexpat1-debuginfo-32bit - update to 2.1.0-21.37.1
expat-debugsource - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
libexpat-devel - addressed in versions 2.1.0-21.37.1, 2.4.4-150400.3.22.1
expat-debuginfo - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
libexpat1-debuginfo - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
expat-debuginfo-32bit - update to 2.1.0-21.37.1
libexpat1-32bit - addressed in versions 2.1.0-21.37.1, 2.4.4-150400.3.22.1
expat - addressed in versions 2.1.0-21.37.1, 2.4.4-150400.3.22.1
libexpat1 - addressed in versions 2.1.0-21.37.1, 2.2.5-150000.3.30.1, 2.4.4-150400.3.22.1
expat-devel - addressed in versions 2.2.5-13.0.1, 2.5.0-4
expat - addressed in versions 2.2.5-13.0.1, 2.5.0-4
expat (Red Hat package) - addressed in versions 2.2.5-15.el8_10, 2.5.0-2.el9_4.1
expat-debugsource - update to 2.2.9-13
expat - update to 2.2.9-13
expat-debuginfo - update to 2.2.9-13
expat-devel - update to 2.2.9-13
expat-help - update to 2.2.9-13
IBM Cloud Pak System - update to 2.3.4.1 iFix 1
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.6, 2.6.3
libexpat1-64bit-debuginfo - update to 2.4.4-150400.3.22.1
expat-64bit-debuginfo - update to 2.4.4-150400.3.22.1
libexpat-devel-64bit - update to 2.4.4-150400.3.22.1
expat-32bit-debuginfo - update to 2.4.4-150400.3.22.1
libexpat-devel-32bit - update to 2.4.4-150400.3.22.1
libexpat1-32bit-debuginfo - update to 2.4.4-150400.3.22.1
libexpat1-64bit - update to 2.4.4-150400.3.22.1
OpenShift Service Mesh - addressed in versions 2.4.11, 2.5.5, 2.5.6, 2.6.2
expat (Debian package) - update to 2.5.0-1+deb12u1
expat-static - update to 2.5.0-4
expat-doc - update to 2.5.0-4
expat - update to 2.6.3
expat - addressed in versions 2.6.3-1.fc39, 2.6.3-1.fc40, 2.6.3-1.fc41
mingw-expat - addressed in versions 2.6.3-1.fc39, 2.6.3-1.fc40, 2.6.3-1.fc41
Cloud Pak for Network Automation - update to 2.7.7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.5, 2.11.3, 2.12.0
OpenManage Network Integration (OMNI) - update to 3.7
python3.8 - addressed in versions 3.8.20-1.fc39, 3.8.20-1.fc40, 3.8.20-1.fc41
python3 - update to 3.9.20
python3.9 - addressed in versions 3.9.20-1.fc39, 3.9.20-1.fc40, 3.9.20-1.fc41
python3.10 - addressed in versions 3.10.15-1.fc39, 3.10.15-1.fc40, 3.10.15-1.fc41
Enterprise SONiC - update to 4.4.1
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.6, 4.5.3
IBM Cloud Pak for Watson AIOps - update to 4.8.1
watsonx Assistant for IBM Cloud Pak for Data - update to 4.8.8
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.13.12, 4.14.11, 4.16.3
Red Hat OpenShift Container Platform - addressed in versions 4.13.52, 4.14.38, 4.15.35, 4.16.15, 4.16.16, 4.17.0, 4.17.1, 4.17.5
App Connect Enterprise Certified Container - addressed in versions 5.0.22, 12.0.6, 12.6.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
watsonx Assistant Cartridge - update to 5.1.1
OpenShift Logging - addressed in versions 5.6.24, 5.6.25, 5.8.13, 5.8.14, 5.9.7, 5.9.8, 6.0.1
iDRAC9 - addressed in versions 7.00.00.181, 7.20.30.50
Precision 7920 Rack - update to 7.00.00.181
Precision 7920 XL Rack - update to 7.00.00.181
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 11
IBM Business Automation Manager Open Editions - update to 8.0.6
PowerScale OneFS - addressed in versions 9.5.1.2, 9.7.1.5, 9.10.0.0
NetWorker Management Console - update to 19.12.0.1
mozjs52-debuginfo - update to 52.6.0-150000.3.9.1
libmozjs-52 - update to 52.6.0-150000.3.9.1
mozjs52 - update to 52.6.0-150000.3.9.1
libmozjs-52-debuginfo - update to 52.6.0-150000.3.9.1
mozjs52-debugsource - update to 52.6.0-150000.3.9.1
mozjs52-devel - update to 52.6.0-150000.3.9.1
libmozjs-60-debuginfo - update to 60.9.0-150200.6.8.1
mozjs60-devel - update to 60.9.0-150200.6.8.1
mozjs60-debuginfo - update to 60.9.0-150200.6.8.1
mozjs60 - update to 60.9.0-150200.6.8.1
libmozjs-60 - update to 60.9.0-150200.6.8.1
mozjs60-debugsource - update to 60.9.0-150200.6.8.1
libmozjs-78-0-debuginfo - update to 78.15.0-150400.3.6.2
libmozjs-78-0 - update to 78.15.0-150400.3.6.2
mozjs78-debuginfo - update to 78.15.0-150400.3.6.2
mozjs78 - update to 78.15.0-150400.3.6.2
mozjs78-debugsource - update to 78.15.0-150400.3.6.2
mozjs78-devel - update to 78.15.0-150400.3.6.2
dev-qt/qtwebengine - update to 103.0.5060.53
mozjs115-debuginfo - update to 115.4.0-150600.3.3.1
mozjs115-devel - update to 115.4.0-150600.3.3.1
libmozjs-115-0-debuginfo - update to 115.4.0-150600.3.3.1
mozjs115 - update to 115.4.0-150600.3.3.1
libmozjs-115-0 - update to 115.4.0-150600.3.3.1
mozjs115-debugsource - update to 115.4.0-150600.3.3.1
IBM Observability with Instana - update to 284
External References
Related Security Bulletins
- Slackware Linux update for expat
- Fedora 41 update for expat
- Fedora 40 update for expat
- Fedora 39 update for expat
- Fedora 39 update for mingw-expat
- Fedora 40 update for mingw-expat
- Fedora 41 update for mingw-expat
- openEuler update for expat
- Slackware Linux update for python3
- SUSE update for expat
- Fedora 41 update for python3.10
- Fedora 40 update for python3.10
- Fedora 39 update for python3.10
- Fedora 41 update for python3.9
- Fedora 40 update for python3.9
- Fedora 39 update for python3.9
- Fedora 39 update for python3.8
- Fedora 41 update for python3.8
- Fedora 40 update for python3.8
- Ubuntu update for libxmltok
- Ubuntu update for expat
- SUSE update for expat
- openEuler update for xmlrpc-c
- OpenBSD update for libexpat
- Ubuntu update for libxmltok
- Ubuntu update for expat
- Debian update for expat
- Red Hat Enterprise Linux 9 update for expat
- Red Hat Enterprise Linux 8 update for expat
- Multiple vulnerabilities in Service Interconnect 1
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- SUSE update for expat
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- SUSE update for mozjs115
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.6
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- SUSE update for mozjs78
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in OpenShift Logging 6.0
- Multiple vulnerabilities in OpenShift Logging 5.8
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM AIX and IBM VIOS
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Service Interconnect 1
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple iPadOS 17
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Service Interconnect
- Multiple vulnerabilities in Enterprise SONiC Distribution
- Fedora 42 update for xmlrpc-c
- Fedora 42 update for xmlrpc-c
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Gentoo update for QtWebEngine
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in IBM watsonx Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- IBM Cloud Pak System update for libexpat
- Multiple vulnerabilities in libexpat
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
- Anolis OS update for expat
- Dell SmartFabric Storage Software update for third-party components
- Dell Data Lakehouse System software update for third-party components
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server
- Meinberg LANTIME firmware update for third-party components (October 2024)
- Dell NetWorker Management Console update for third-party components
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Dell iDRAC9
- Multiple vulnerabilities in Dell Precision Rack
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Anolis OS update for expat
- Multiple vulnerabilities in IBM OpenPages
- SUSE update for mozjs52
- SUSE update for mozjs60
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access
- Multiple vulnerabilities in IBM Netezza Analytics for NPS