{"id":"CVE-2023-5685","title":"A flaw was found in XNIO","summary":"A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400"],"vendor":"Red Hat","product":"xnio","affected":["xnio","org.jboss.xnio/xnio-nio (all versions)","eap7-apache-cxf (all versions)","eap7-avro (all versions)","eap7-bouncycastle (all versions)","eap7-h2database (all versions)","eap7-jackson-databind (all versions)","eap7-jboss-marshalling (all versions)","eap7-jboss-xnio-base (all versions)","eap7-wildfly (all versions)","eap7-xalan-j2 (all versions)","eap7-apache-cxf (all versions)","eap7-avro (all versions)","eap7-h2database (all versions)","eap7-jboss-annotations-api_1.3_spec (all versions)","eap7-jboss-marshalling (all versions)","eap7-jboss-server-migration (all versions)","eap7-jboss-xnio-base (all versions)","eap7-log4j-jboss-logmanager (all versions)","eap7-wildfly (all versions)","eap7-wss4j (all versions)","eap7-xalan-j2 (all versions)","eap7-xml-security (all versions)","eap7-jboss-xnio-base (all versions)","eap7-jboss-xnio-base (all versions)","eap7-jboss-xnio-base (all versions)","xnio","xnio (all versions)","xnio","xnio","xnio (all versions)","xnio","xnio-nio","xnio-nio","xnio","xnio (all versions)","xnio"],"published":"2024-03-22","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:16:36.733","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-5685","references":[{"url":"https://access.redhat.com/errata/RHSA-2023:7637","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7638","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7639","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7641","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:10207","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:10208","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2707","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2023-5685","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2241822","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7637","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7638","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7639","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7641","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2707","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2023-5685","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2241822","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5685.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-5685"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5685"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2024-04-22T16:12:35.889624Z"},"epss":0.03479,"epssPercentile":0.8858,"ingestedAt":"2026-09-14T20:14:21.154Z","patched":["jboss_enterprise_application_platform_7_1_eus_for_rhel_7_server","jboss_enterprise_application_platform_7_3_eus_for_rhel_7_server","jboss_eap_7_4_for_rhel_7_server","jboss_eap_7_4_for_rhel 8","jboss_eap_7_4_for_rhel 9","jboss_enterprise_application_platform","build_of_apache_camel_4_4_0_for_spring_boot"],"slug":"CVE-2023-5685","body":"## Overview\n\nA flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2024:10208** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · released 2024-11-25 · [advisory](https://access.redhat.com/errata/RHSA-2024:10208)\n- **RHSA-2024:10207** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2024-11-25 · [advisory](https://access.redhat.com/errata/RHSA-2024:10207)\n- **RHSA-2023:7637** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7637)\n- **RHSA-2023:7638** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7638)\n- **RHSA-2023:7639** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 9 · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7639)\n- **RHSA-2023:7641** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7641)\n- **RHSA-2024:2707** · Red Hat · fixed in: Red Hat build of Apache Camel 4.4.0 for Spring Boot · released 2024-05-06 · [advisory](https://access.redhat.com/errata/RHSA-2024:2707)\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat Integration Camel K 1, Red Hat JBoss Data Grid 7, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7 · no fix planned: Red Hat JBoss Data Grid 7, Red Hat JBoss Fuse Service Works 6, Red Hat build of Apache Camel - HawtIO 4, Red Hat Integration Camel K 1, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5685.json)","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.7,"exploitation":0,"ransomware":0},"changes":[]}