High [CVE-2023-5685] Xnio: stackoverflowexception when the chain of notifier states becomes problematically big
This high-severity Red Hat Linux advisory covers CVE-2023-5685 affecting Red Hat build of Apache Camel 4.4.0 for Spring Boot, Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7, Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).
Red Hat rates this vulnerability as an Important impact as the uncontrolled resource consumption may lead to Denial of Service (DoS). This might be intentioned by an attacker who is looking to jeopardize an environment.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400.
Affected Red Hat products: Red Hat build of Apache Camel 4.4.0 for Spring Boot; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7; Red Hat build of Apache Camel - HawtIO 4; Red Hat Integration Camel K 1; Red Hat JBoss Data Grid 7; Red Hat JBoss Fuse Service Works 6; Red Hat Process Automation 7.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
- xnio
- eap7-apache-cxf-0:3.1.16-3.SP1_redhat_00001.1.ep7.el7
- eap7-avro-0:1.7.6-2.redhat_00003.1.ep7.el7
- eap7-bouncycastle-0:1.68.0-1.redhat_00005.1.ep7.el7
- eap7-h2database-0:1.4.197-2.redhat_00005.1.ep7.el7
- eap7-jackson-databind-0:2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
- eap7-jboss-marshalling-0:2.0.15-1.Final_redhat_00001.1.ep7.el7
- eap7-jboss-xnio-base-0:3.5.10-1.Final_redhat_00001.1.ep7.el7
- eap7-wildfly-0:7.1.8-2.GA_redhat_00002.1.ep7.el7
- eap7-xalan-j2-0:2.7.1-26.redhat_00015.1.ep7.el7
- eap7-apache-cxf-0:3.4.10-1.SP1_redhat_00001.1.el7eap
- eap7-avro-0:1.7.6-8.redhat_00003.1.el7eap
- eap7-h2database-0:1.4.197-3.redhat_00004.1.el7eap
- eap7-jboss-annotations-api_1.3_spec-0:2.0.1-4.Final_redhat_00001.1.el7eap
- eap7-jboss-marshalling-0:2.0.15-1.Final_redhat_00001.1.el7eap
- eap7-jboss-server-migration-0:1.7.2-12.Final_redhat_00013.1.el7eap
- eap7-jboss-xnio-base-0:3.7.13-1.Final_redhat_00001.1.el7eap
- eap7-log4j-jboss-logmanager-0:1.2.2-2.Final_redhat_00002.1.el7eap
- eap7-wildfly-0:7.3.11-4.GA_redhat_00002.1.el7eap
- eap7-wss4j-0:2.3.3-2.redhat_00001.1.el7eap
- eap7-xalan-j2-0:2.7.1-38.redhat_00015.1.el7eap
- eap7-xml-security-0:2.2.3-2.redhat_00001.1.el7eap
- eap7-jboss-xnio-base-0:3.8.11-1.SP1_redhat_00001.1.el8eap
- eap7-jboss-xnio-base-0:3.8.11-1.SP1_redhat_00001.1.el9eap
- eap7-jboss-xnio-base-0:3.8.11-1.SP1_redhat_00001.1.el7eap
- RHSA-2024:2707
- RHSA-2023:7641
- RHSA-2024:10208
- RHSA-2024:10207
- RHSA-2023:7638
- RHSA-2023:7639
- RHSA-2023:7637
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- There is currently no mitigation available for this vulnerability. Please keep the packages up-to-date as the updates become available.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.