https://seclists.org/oss-sec/2025/q1/221: [CVE-2024-8176] Long linear chains of entities crash Expat with stack overflow due to use of unlimited cursion
Published Mar 14, 2025
·Updated
Affected Software
1 affected component
Expat libexpat<2.7.0
Frequently Asked Questions
1
What is the severity of CVE-2024-8176?
CVE-2024-8176 has been classified as a high severity vulnerability due to its potential to cause a stack overflow.
2
How do I fix CVE-2024-8176?
To address CVE-2024-8176, upgrade to Expat version 2.6.2 or later, which includes the necessary security fixes.
3
What type of vulnerability is CVE-2024-8176?
CVE-2024-8176 is a stack overflow vulnerability caused by the processing of long linear chains of entities in Expat.
4
What software is affected by CVE-2024-8176?
CVE-2024-8176 affects the Expat XML parser, specifically the libexpat library.
5
When was CVE-2024-8176 published?
CVE-2024-8176 was published on March 14, 2025.