{"schema_version":"1.9.0","id":"CVE-2024-8176","published":"2025-03-14T08:19:48.962Z","modified":"2026-08-31T11:47:37.005407290Z","related":["ALSA-2025:3531","ALSA-2025:3913","ALSA-2025:4048","ALSA-2025:7444","ALSA-2025:7512","CGA-4xpp-7q79-mwcw","SUSE-SU-2025:03239-1","SUSE-SU-2025:1186-1","SUSE-SU-2025:1201-1","SUSE-SU-2025:1295-1","SUSE-SU-2025:20207-1","SUSE-SU-2025:20311-1","openSUSE-SU-2025:14952-1"],"summary":"Libexpat: expat: improper restriction of xml entity expansion depth in libexpat","details":"A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libexpat/libexpat","events":[{"introduced":"0"},{"fixed":"6d4ffe856df497ac2cae33537665c3fec7ec8a00"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.7.0"}],"source":"AFFECTED_FIELD"}}],"versions":["R_2_6_4","R_2_6_3","R_2_6_2","R_2_6_1","R_2_6_0","R_2_5_0","R_2_4_9","R_2_4_8","R_2_4_7","R_2_4_6","R_2_4_5","R_2_4_4","R_2_4_3","R_2_4_2","R_2_4_1","R_2_4_0","R_2_3_0","R_2_2_10","R_2_2_9","R_2_2_8","R_2_2_7","R_2_2_6","R_2_2_5","R_2_2_4","R_2_2_3","R_2_2_2","R_2_2_1","R_2_2_0","R_2_1_1","R_2_1_0","R_2_0_1","R_2_0_0","R_1_95_8","R_1_95_7","R_1_95_6","R_1_95_5","R_1_95_4","R_1_95_3","R_1_95_2","R_1_95_0","libexpat-alpha-1","start","sourceforge_init","jclark-orig","V20000512","V19991013","V19990728","V19990709","V19990626","V1_1","V19990425","V1990307","V19990109","V19981231","V19981122","V1_0","beta4","beta3","beta2","REC1_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8176.json"}}],"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/May/10"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/May/11"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/May/12"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/May/6"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/May/7"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2025/May/8"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/03/15/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/09/24/11"},{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"WEB","url":"https://github.com/libexpat/libexpat/"},{"type":"WEB","url":"https://github.com/libexpat/libexpat/blob/R_2_7_0/expat/Changes#L40-L52"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2024-8176"},{"type":"WEB","url":"https://ubuntu.com/security/CVE-2024-8176"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/760160"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:13681"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22033"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22034"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22035"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22607"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22785"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22842"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:22871"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:3531"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:3734"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:3913"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:4048"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:4446"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:4447"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:4448"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:4449"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:7444"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:7512"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:8385"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-8176"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8176.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8176"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250328-0009/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2310137"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1239618"},{"type":"REPORT","url":"https://github.com/libexpat/libexpat/issues/893"},{"type":"FIX","url":"https://github.com/libexpat/libexpat/pull/973"},{"type":"FIX","url":"https://gitlab.alpinelinux.org/alpine/aports/-/commit/d068c3ff36fc6f4789988a09c69b434db757db53"},{"type":"ARTICLE","url":"https://blog.hartwork.org/posts/expat-2-7-0-released/"}],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-674"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8176.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}