Bug 2241822 (CVE-2023-5685) - CVE-2023-5685 xnio: StackOverflowException when the chain of notifier states becomes problematically big [NEEDINFO]
Summary: CVE-2023-5685 xnio: StackOverflowException when the chain of notifier states ...
Keywords:
Status: NEW
Alias: CVE-2023-5685
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2241803
TreeView+ depends on / blocked
 
Reported: 2023-10-02 20:16 UTC by Patrick Del Bello
Modified: 2025-11-15 06:59 UTC (History)
66 users (show)

Fixed In Version: xnio 3.8.14, xnio 3.8.12.SP1, xnio 3.8.11.SP1
Clone Of:
Environment:
Last Closed:
Embargoed:
davidrobert0301234: needinfo? (abrianik)
john0304.com: needinfo? (abrianik)
t3937241: needinfo? (abrianik)
vname246: needinfo? (abrianik)


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:7641 0 None None None 2025-10-23 22:34:21 UTC
Red Hat Product Errata RHSA-2024:10207 0 None None None 2024-11-25 00:11:45 UTC
Red Hat Product Errata RHSA-2024:10208 0 None None None 2024-11-25 00:10:40 UTC
Red Hat Product Errata RHSA-2024:2707 0 None None None 2024-05-06 14:10:22 UTC

Description Patrick Del Bello 2023-10-02 20:16:31 UTC
A flaw was found under XNIO. XNIO NotifierState can cause StackOverflowException when the chain of notifier states becomes problematically big and that may lead to an uncontrolled resource management and lead to a possible Denial of Service (DoS).

Comment 5 James Howe 2024-03-07 14:29:57 UTC
> xnio 3.8.14

When will this release be available? It's not yet in Maven Central, for example.

Comment 6 Salvatore Bonaccorso 2024-03-10 14:18:16 UTC
Hi

Can you provide a reference to the upstream commit fixing this issue? While there seems to be a preparation commit for the next 3.8.14.Final in https://github.com/xnio/xnio/commit/9b3ce71411688969cb455e5c1b62dce8303bd80e I could not find something related to this description.

Is there an upstream (public) issue for this?

Comment 7 Patrick Del Bello 2024-03-13 17:01:30 UTC
Hi @carnil,

I just checked with the maintainers. Please watch this page https://issues.redhat.com/browse/WFCORE-6738
The details will be added as their are working in a backport

Comment 8 James Howe 2024-03-21 12:46:59 UTC
The work was done here: https://issues.redhat.com/browse/XNIO-423

The problem is these `next` calls: https://github.com/xnio/xnio/blob/3.8.13.Final/api/src/main/java/org/xnio/AbstractIoFuture.java#L249

Release 3.8.14 (https://issues.redhat.com/projects/XNIO/versions/12423148) does not currently have an estimated release date.

Comment 9 StevenSantiago 2024-04-09 05:03:09 UTC Comment hidden (spam)
Comment 13 errata-xmlrpc 2024-05-06 14:10:19 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.4.0 for Spring Boot

Via RHSA-2024:2707 https://access.redhat.com/errata/RHSA-2024:2707

Comment 14 jaydenz 2024-07-10 07:30:18 UTC Comment hidden (spam)
Comment 15 James Howe 2024-07-10 10:01:28 UTC Comment hidden (obsolete)
Comment 16 Kaden Compton 2024-09-17 07:35:30 UTC Comment hidden (spam)
Comment 18 errata-xmlrpc 2024-11-25 00:10:37 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7

Via RHSA-2024:10208 https://access.redhat.com/errata/RHSA-2024:10208

Comment 19 errata-xmlrpc 2024-11-25 00:11:42 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7

Via RHSA-2024:10207 https://access.redhat.com/errata/RHSA-2024:10207

Comment 23 tamilyogifree 2025-04-17 18:29:57 UTC Comment hidden (spam)
Comment 24 VMUSIC 2025-04-18 19:30:14 UTC Comment hidden (spam)
Comment 26 errata-xmlrpc 2025-10-23 22:34:16 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7

Via RHSA-2023:7641 https://access.redhat.com/errata/RHSA-2023:7641

Comment 27 david robert 2025-11-10 06:49:45 UTC
This is a beautifully crafted warp drive sound effect. The smooth tonal rise and futuristic modulation create a strong sense of acceleration, making it perfect for sci-fi transitions, spaceship travel scenes, or cinematic intros. I also tested it in CapCut, and it blends very well with motion graphics and speed-ramp edits especially for space-themed video projects or travel transition clips. Excellent work, very clean and highly usable. visit: https://thecupcut.com/

Comment 29 john mubarak 2025-11-15 06:53:29 UTC
This warp drive sound effect is exceptionally well crafted. The smooth tonal rise and futuristic modulation create a powerful sense of acceleration, making it ideal for sci-fi transitions, spaceship travel scenes, and cinematic intros. I also tested it in CapCut, and it blends seamlessly with motion graphics and speed-ramp edits—especially for space-themed visuals or dynamic travel transitions. Overall, a clean, high-quality, and very versatile sound. Great work! visit:https://vscoedit.com/

Comment 30 thomas aboya 2025-11-15 06:57:58 UTC
Outstanding sound design! The warp drive effect delivers a clean, immersive rise with just the right amount of futuristic texture. It instantly adds depth to sci-fi edits, cinematic sequences, and high-energy transitions. I tried it in CapCut as well, and it syncs beautifully with motion graphics and fast-paced visual effects. A highly usable and well-produced sound—excellent job! visit:https://instanderaps.com/

Comment 31 vender merwe 2025-11-15 06:59:11 UTC
Impressive quality! The warp drive sound has a smooth, atmospheric build-up that perfectly captures the feel of futuristic travel. It works amazingly well in sci-fi edits, game trailers, and cinematic transitions. I tested it in CapCut too, and it layers effortlessly with visual effects and speed ramps. Really clean, dynamic, and production-ready—great work! visit: https://trafficracermod.com/


Note You need to log in before you can comment on or make changes to this bug.