Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 951316 (CVE-2024-8176) - <dev-libs/expat-2.7.0 can be crashed through long linear chains of entities
Summary: <dev-libs/expat-2.7.0 can be crashed through long linear chains of entities
Status: IN_PROGRESS
Alias: CVE-2024-8176
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://blog.hartwork.org/posts/expat...
Whiteboard: B3 [glsa? cleanup]
Keywords:
Depends on: 951356
Blocks:
  Show dependency tree
 
Reported: 2025-03-13 21:42 UTC by Sebastian Pipping
Modified: 2025-04-14 14:32 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Pipping gentoo-dev 2025-03-13 21:42:46 UTC
- Please see URL field for the blog post with details.
- Bump to 2.7.0 coming up in a minute…
Comment 1 Larry the Git Cow gentoo-dev 2025-03-13 21:44:50 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=bbe241ea7747494b118969bf2cf4e03118a0267a

commit bbe241ea7747494b118969bf2cf4e03118a0267a
Author:     Sebastian Pipping <sping@gentoo.org>
AuthorDate: 2025-03-13 21:37:23 +0000
Commit:     Sebastian Pipping <sping@gentoo.org>
CommitDate: 2025-03-13 21:43:16 +0000

    dev-libs/expat: 2.7.0 (CVE-2024-8176)
    
    Bug: https://bugs.gentoo.org/951316
    Signed-off-by: Sebastian Pipping <sping@gentoo.org>

 dev-libs/expat/Manifest           |   1 +
 dev-libs/expat/expat-2.7.0.ebuild | 100 ++++++++++++++++++++++++++++++++++++++
 2 files changed, 101 insertions(+)
Comment 2 Sebastian Pipping gentoo-dev 2025-03-28 15:28:31 UTC
I have taken the issue to CERT/CC VINCE also to notify more vendors of the
issue.  Gentoo Linux was added as a vendor by the coordinator.  Could someone
with permissions in VINCE mark vendor Gentoo Linux as "affected" for not-yet-
public case https://kb.cert.org/vince/comm/case/2322/ ?  Thanks!
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-03-28 15:53:56 UTC
I'll do that now, thanks
Comment 4 Sebastian Pipping gentoo-dev 2025-03-28 16:08:55 UTC
(In reply to Sam James from comment #3)
> I'll do that now, thanks

Thank you!