---
id: CVE-2023-5685
title: A flaw was found in XNIO
summary: >-
  A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack
  Overflow Exception when the chain of notifier states becomes problematically
  large can lead to uncontrolled resource management and a possible denial of
  service (DoS).
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: Red Hat
product: xnio
affected:
  - xnio
  - org.jboss.xnio/xnio-nio (all versions)
  - eap7-apache-cxf (all versions)
  - eap7-avro (all versions)
  - eap7-bouncycastle (all versions)
  - eap7-h2database (all versions)
  - eap7-jackson-databind (all versions)
  - eap7-jboss-marshalling (all versions)
  - eap7-jboss-xnio-base (all versions)
  - eap7-wildfly (all versions)
  - eap7-xalan-j2 (all versions)
  - eap7-apache-cxf (all versions)
  - eap7-avro (all versions)
  - eap7-h2database (all versions)
  - eap7-jboss-annotations-api_1.3_spec (all versions)
  - eap7-jboss-marshalling (all versions)
  - eap7-jboss-server-migration (all versions)
  - eap7-jboss-xnio-base (all versions)
  - eap7-log4j-jboss-logmanager (all versions)
  - eap7-wildfly (all versions)
  - eap7-wss4j (all versions)
  - eap7-xalan-j2 (all versions)
  - eap7-xml-security (all versions)
  - eap7-jboss-xnio-base (all versions)
  - eap7-jboss-xnio-base (all versions)
  - eap7-jboss-xnio-base (all versions)
  - xnio
  - xnio (all versions)
  - xnio
  - xnio
  - xnio (all versions)
  - xnio
  - xnio-nio
  - xnio-nio
  - xnio
  - xnio (all versions)
  - xnio
published: '2024-03-22'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:16:36.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-5685'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:7637'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7638'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7639'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7641'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:10207'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:10208'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2707'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-5685'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2241822'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7637'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7638'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7639'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7641'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2707'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-5685'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2241822'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5685.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-5685'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-5685'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2024-04-22T16:12:35.889624Z'
epss: 0.03479
epssPercentile: 0.88595
ingestedAt: '2026-09-14T20:14:21.154Z'
patched:
  - jboss_enterprise_application_platform_7_1_eus_for_rhel_7_server
  - jboss_enterprise_application_platform_7_3_eus_for_rhel_7_server
  - jboss_eap_7_4_for_rhel_7_server
  - jboss_eap_7_4_for_rhel 8
  - jboss_eap_7_4_for_rhel 9
  - jboss_enterprise_application_platform
  - build_of_apache_camel_4_4_0_for_spring_boot
---

## Overview

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2024:10208** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · released 2024-11-25 · [advisory](https://access.redhat.com/errata/RHSA-2024:10208)
- **RHSA-2024:10207** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2024-11-25 · [advisory](https://access.redhat.com/errata/RHSA-2024:10207)
- **RHSA-2023:7637** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7637)
- **RHSA-2023:7638** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7638)
- **RHSA-2023:7639** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 9 · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7639)
- **RHSA-2023:7641** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2023-12-04 · [advisory](https://access.redhat.com/errata/RHSA-2023:7641)
- **RHSA-2024:2707** · Red Hat · fixed in: Red Hat build of Apache Camel 4.4.0 for Spring Boot · released 2024-05-06 · [advisory](https://access.redhat.com/errata/RHSA-2024:2707)
- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat Integration Camel K 1, Red Hat JBoss Data Grid 7, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7 · no fix planned: Red Hat JBoss Data Grid 7, Red Hat JBoss Fuse Service Works 6, Red Hat build of Apache Camel - HawtIO 4, Red Hat Integration Camel K 1, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-5685.json)
