CVE-2024-8176: Red Hat Devworkspace Operator 0.33
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.
Affected products
- Red Hat Devworkspace Operator 0.33: before 0.33-1744075017 (fixed in 0.33-1744075017)
- Red Hat Red Hat Discovery 1.14: before 1.14.3-1748529279 (fixed in 1.14.3-1748529279); before 1.14.2-1748467619 (fixed in 1.14.2-1748467619)
- Red Hat Red Hat Enterprise Linux 10: before 0:2.7.1-1.el10_0 (fixed in 0:2.7.1-1.el10_0)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 0:2.2.5-17.el8_10 (fixed in 0:2.2.5-17.el8_10); before 0:1.51.0-11.el8_10 (fixed in 0:1.51.0-11.el8_10)
- Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:2.2.10-1.el8_2 (fixed in 0:2.2.10-1.el8_2); before 0:1.51.0-5.el8_2.2 (fixed in 0:1.51.0-5.el8_2.2)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:2.2.10-1.el8_4 (fixed in 0:2.2.10-1.el8_4); before 0:1.51.0-5.el8_4.2 (fixed in 0:1.51.0-5.el8_4.2)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:2.2.10-1.el8_4 (fixed in 0:2.2.10-1.el8_4)
- Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service: before 0:1.51.0-5.el8_4.2 (fixed in 0:1.51.0-5.el8_4.2)
- Red Hat Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions: before 0:1.51.0-5.el8_4.2 (fixed in 0:1.51.0-5.el8_4.2)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:2.2.10-1.el8_6 (fixed in 0:2.2.10-1.el8_6); before 0:1.51.0-6.el8_6.1 (fixed in 0:1.51.0-6.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:2.2.10-1.el8_6 (fixed in 0:2.2.10-1.el8_6); before 0:1.51.0-6.el8_6.1 (fixed in 0:1.51.0-6.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:2.2.10-1.el8_6 (fixed in 0:2.2.10-1.el8_6); before 0:1.51.0-6.el8_6.1 (fixed in 0:1.51.0-6.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 0:1.51.0-8.el8_8.1 (fixed in 0:1.51.0-8.el8_8.1)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:2.2.10-1.el8_8 (fixed in 0:2.2.10-1.el8_8)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:2.2.10-1.el8_8 (fixed in 0:2.2.10-1.el8_8)
- Red Hat Red Hat Enterprise Linux 9: before 0:2.5.0-3.el9_5.3 (fixed in 0:2.5.0-3.el9_5.3); before 0:2.5.0-5.el9_6 (fixed in 0:2.5.0-5.el9_6)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:2.2.10-12.el9_0.4 (fixed in 0:2.2.10-12.el9_0.4)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:2.5.0-1.el9_2.3 (fixed in 0:2.5.0-1.el9_2.3)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:2.5.0-2.el9_4.3 (fixed in 0:2.5.0-2.el9_4.3)
- Red Hat Red Hat Openshift Container Platform 4
Published 2025-03-14. Last modified 2026-09-21.