Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:1615 - Security Advisory
Issued:
2024-04-02
Updated:
2024-04-02

RHSA-2024:1615 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: expat security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for expat is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Expat is a C library for parsing XML documents.

Security Fix(es):

  • expat: parsing large tokens can trigger a denial of service (CVE-2023-52425)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing the updated packages, applications using the Expat library must be restarted for the update to take effect.

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2262877 - CVE-2023-52425 expat: parsing large tokens can trigger a denial of service

CVEs

  • CVE-2023-52425

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
expat-2.2.5-11.el8_9.1.src.rpm SHA-256: 662aaa0e5e169e24f6b27e7bd79c608d8f663f104aad8fc00dc9e19573789b30
x86_64
expat-2.2.5-11.el8_9.1.i686.rpm SHA-256: 72fe88791b456d70ec19cb93ce818626da38571758123b12b2b1ba1f78181bfa
expat-2.2.5-11.el8_9.1.x86_64.rpm SHA-256: 7eed8d387e2bb7b4a4dfe22574560cdf47c54b3eaa403c2bbac52bb3b663b914
expat-debuginfo-2.2.5-11.el8_9.1.i686.rpm SHA-256: 06680461cb456bcdbb572b0ddef567e30ffaef01448997bf526d7ef668239419
expat-debuginfo-2.2.5-11.el8_9.1.x86_64.rpm SHA-256: 7ad95972fea001c2cf1a800f34214a3f6f7e2767174e9c1dfac635725d97beed
expat-debugsource-2.2.5-11.el8_9.1.i686.rpm SHA-256: fa0ceffd4039f7bab60eda0239e053215779dc9673769986744f611115302d8f
expat-debugsource-2.2.5-11.el8_9.1.x86_64.rpm SHA-256: d2c870d0458759cdd35470bff0f4ae112c5e2777926059d0d7a7697ee430bd69
expat-devel-2.2.5-11.el8_9.1.i686.rpm SHA-256: 7e46b30713bf08e56e047680a8ff9e4528e9e701aa1611730539c3eb9d174a82
expat-devel-2.2.5-11.el8_9.1.x86_64.rpm SHA-256: 3168fc7a4618823203a82fe5c8494d19e254c028351e2bbca1d21af2cddbe282

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
expat-2.2.5-11.el8_9.1.src.rpm SHA-256: 662aaa0e5e169e24f6b27e7bd79c608d8f663f104aad8fc00dc9e19573789b30
s390x
expat-2.2.5-11.el8_9.1.s390x.rpm SHA-256: 68cf6c9d16a369991a4519921dc1c8628b7143fade3d4246ba4b0666c32c42ff
expat-debuginfo-2.2.5-11.el8_9.1.s390x.rpm SHA-256: 3cc964519de043f0b5cce81e8d0cff51eea33a49e3023b7790118ddbac450094
expat-debugsource-2.2.5-11.el8_9.1.s390x.rpm SHA-256: 3a3403c1e61cfce7ffc1b593c190638ce8cca6e6b7e394eab90a3d1a00fe8e6d
expat-devel-2.2.5-11.el8_9.1.s390x.rpm SHA-256: 4b916b445f5b6d7e12530b960b6f72c53449b1e2020bb90a0377a1f8f186e8ad

Red Hat Enterprise Linux for Power, little endian 8

SRPM
expat-2.2.5-11.el8_9.1.src.rpm SHA-256: 662aaa0e5e169e24f6b27e7bd79c608d8f663f104aad8fc00dc9e19573789b30
ppc64le
expat-2.2.5-11.el8_9.1.ppc64le.rpm SHA-256: d50c8e03cd2fc05588b49164c5f1eb60fcc40f9cc2a3c4d2d3ea9d1f219734aa
expat-debuginfo-2.2.5-11.el8_9.1.ppc64le.rpm SHA-256: 100cb3d3723584ee0d6dd8395bb2408073c47cd55382e76c6df87f0f4b2464ac
expat-debugsource-2.2.5-11.el8_9.1.ppc64le.rpm SHA-256: 929566c593228e80a61548dd63eb29f000476f3f334000f5e1231a89f5c022b5
expat-devel-2.2.5-11.el8_9.1.ppc64le.rpm SHA-256: 7f7f962f0f309ea9f5ee0b1773379043123b51ed25766301c36c5abf51a784ca

Red Hat Enterprise Linux for ARM 64 8

SRPM
expat-2.2.5-11.el8_9.1.src.rpm SHA-256: 662aaa0e5e169e24f6b27e7bd79c608d8f663f104aad8fc00dc9e19573789b30
aarch64
expat-2.2.5-11.el8_9.1.aarch64.rpm SHA-256: 48f5e2aae1774df5696ef3a8630fa339efdb2add84eb586ca2d50a75997918c0
expat-debuginfo-2.2.5-11.el8_9.1.aarch64.rpm SHA-256: 1d8ccf46931d0e8d43585ed1da82eb2c2f8edabb494ecc0869099e07a9514dcf
expat-debugsource-2.2.5-11.el8_9.1.aarch64.rpm SHA-256: f16929a899debce7e5db282d7eec2a03095ccdd24342063b499ef4f63e7abe92
expat-devel-2.2.5-11.el8_9.1.aarch64.rpm SHA-256: 4405bf10e67e0df37f0cb9acb715777b4997bf388d6960e2f06e8dbf08252b89

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility