Skip to content
VulniPulse
High7.5Red Hat Linux

High [CVE-2023-5685] Xnio: stackoverflowexception when the chain of notifier states becomes problematically big

This high-severity Red Hat Linux advisory covers CVE-2023-5685 affecting Red Hat build of Apache Camel 4.4.0 for Spring Boot, Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7, Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7.

CVE-2023-5685 Published Mar 22, 2024Updated by vendor Mar 5, 2024
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

Red Hat rates this vulnerability as an Important impact as the uncontrolled resource consumption may lead to Denial of Service (DoS). This might be intentioned by an attacker who is looking to jeopardize an environment.

Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400.

Affected Red Hat products: Red Hat build of Apache Camel 4.4.0 for Spring Boot; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7; Red Hat build of Apache Camel - HawtIO 4; Red Hat Integration Camel K 1; Red Hat JBoss Data Grid 7; Red Hat JBoss Fuse Service Works 6; Red Hat Process Automation 7.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Fixed versions
  • xnio
  • eap7-apache-cxf-0:3.1.16-3.SP1_redhat_00001.1.ep7.el7
  • eap7-avro-0:1.7.6-2.redhat_00003.1.ep7.el7
  • eap7-bouncycastle-0:1.68.0-1.redhat_00005.1.ep7.el7
  • eap7-h2database-0:1.4.197-2.redhat_00005.1.ep7.el7
  • eap7-jackson-databind-0:2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
  • eap7-jboss-marshalling-0:2.0.15-1.Final_redhat_00001.1.ep7.el7
  • eap7-jboss-xnio-base-0:3.5.10-1.Final_redhat_00001.1.ep7.el7
  • eap7-wildfly-0:7.1.8-2.GA_redhat_00002.1.ep7.el7
  • eap7-xalan-j2-0:2.7.1-26.redhat_00015.1.ep7.el7
  • eap7-apache-cxf-0:3.4.10-1.SP1_redhat_00001.1.el7eap
  • eap7-avro-0:1.7.6-8.redhat_00003.1.el7eap
  • eap7-h2database-0:1.4.197-3.redhat_00004.1.el7eap
  • eap7-jboss-annotations-api_1.3_spec-0:2.0.1-4.Final_redhat_00001.1.el7eap
  • eap7-jboss-marshalling-0:2.0.15-1.Final_redhat_00001.1.el7eap
  • eap7-jboss-server-migration-0:1.7.2-12.Final_redhat_00013.1.el7eap
  • eap7-jboss-xnio-base-0:3.7.13-1.Final_redhat_00001.1.el7eap
  • eap7-log4j-jboss-logmanager-0:1.2.2-2.Final_redhat_00002.1.el7eap
  • eap7-wildfly-0:7.3.11-4.GA_redhat_00002.1.el7eap
  • eap7-wss4j-0:2.3.3-2.redhat_00001.1.el7eap
  • eap7-xalan-j2-0:2.7.1-38.redhat_00015.1.el7eap
  • eap7-xml-security-0:2.2.3-2.redhat_00001.1.el7eap
  • eap7-jboss-xnio-base-0:3.8.11-1.SP1_redhat_00001.1.el8eap
  • eap7-jboss-xnio-base-0:3.8.11-1.SP1_redhat_00001.1.el9eap
  • eap7-jboss-xnio-base-0:3.8.11-1.SP1_redhat_00001.1.el7eap
  • RHSA-2024:2707
  • RHSA-2023:7641
  • RHSA-2024:10208
  • RHSA-2024:10207
  • RHSA-2023:7638
  • RHSA-2023:7639
  • RHSA-2023:7637

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • There is currently no mitigation available for this vulnerability. Please keep the packages up-to-date as the updates become available.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.