<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:52:30.560628+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7524</id>
    <title>ALSA-2022:7524 — Moderate: yajl security update</title>
    <updated>2026-10-03T16:52:30.873137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: yajl, AlmaLinux:8: yajl-devel</p>
<p>Yet Another JSON Library (YAJL) is a small event-driven (SAX-style) JSON parser written in ANSI C and a small validating JSON generator.</p>
<p>Security Fix(es):</p>
<p>* yajl: heap-based buffer overflow when handling large inputs due to an integer overflow (CVE-2022-24795)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07630</id>
    <title>bdu:2023-07630</title>
    <updated>2026-10-03T16:52:30.873206+00:00</updated>
    <content>bdu:2023-07630</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-yajl-cve-2022-24795</id>
    <title>BREW-yajl-CVE-2022-24795 — Buffer Overflow and Integer Overflow in yajl-ruby</title>
    <updated>2026-10-03T16:52:30.873226+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: yajl</p>
<p>yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf-&gt;alloc into a small heap chunk. These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer. Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. This vulnerability mostly impacts process availability. Maintainers believe exploitation for arbitrary code execution is unlikely. A patch is available and anticipated to be part of yajl-ruby version 1.4.2. As a workaround, avoid passing large inputs to YAJL.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-yajl-cve-2022-24795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0003</id>
    <title>certfr-2025-avi-0003 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T16:52:30.873260+00:00</updated>
    <content>certfr-2025-avi-0003</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232776</id>
    <title>EUVD-2026-232776</title>
    <updated>2026-10-03T16:52:30.873278+00:00</updated>
    <content>EUVD-2026-232776</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232776"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24795</id>
    <title>fkie_cve-2022-24795</title>
    <updated>2026-10-03T16:52:30.873290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf-&gt;alloc into a small heap chunk. These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer. Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. This vulnerability mostly impacts process availability. Maintainers believe exploitation for arbitrary code execution is unlikely. A patch is available and anticipated to be part of yajl-ruby version 1.4.2. As a workaround, avoid passing large inputs to YAJL.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jj47-x69x-mxrm</id>
    <title>GHSA-jj47-x69x-mxrm — Buffer Overflow in yajl-ruby</title>
    <updated>2026-10-03T16:52:30.873321+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: yajl-ruby</p>
<p>_NOTE: A previous patch, 1.4.2, fixed the heap memory issue, but could still lead to a DoS infinite loop. Please update to version 1.4.3_</p>
<p>The 1.x branch and the 2.x branch of [yajl](https://github.com/lloyd/yajl) contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs.</p>
<p>### Details</p>
<p>The [reallocation logic at yajl_buf.c#L64](https://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64) may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf-&gt;alloc into a small heap chunk.</p>
<p>These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer.</p>
<p>Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption.</p>
<p>### Impact</p>
<p>We rate this as a moderate severity vulnerability which mostly impacts process availability as we believe exploitation for arbitrary code execution to be unlikely.</p>
<p>### Patches</p>
<p>Patched in yajl-ruby 1.4.3</p>
<p>### Workarounds</p>
<p>Avoid passing large inputs to YAJL</p>
<p>### References
https://github.com/brianmario/yajl-ruby/blob/7168bd79b888900aa94523301126f968a93eb3a6/ext/yajl/yajl_buf.c#L64</p>
<p>### For more information
If you…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jj47-x69x-mxrm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24795</id>
    <title>gsd-2022-24795</title>
    <updated>2026-10-03T16:52:30.873369+00:00</updated>
    <content>gsd-2022-24795</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-24795</id>
    <title>msrc_CVE-2022-24795 — Buffer Overflow and Integer Overflow in yajl-ruby</title>
    <updated>2026-10-03T16:52:30.873382+00:00</updated>
    <content>msrc_CVE-2022-24795</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-24795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1752</id>
    <title>OESA-2022-1752 — rubygem-yajl-ruby security update</title>
    <updated>2026-10-03T16:52:30.873399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rubygem-yajl-ruby, openEuler:20.03-LTS-SP3: rubygem-yajl-ruby, openEuler:22.03-LTS: rubygem-yajl-ruby</p>
<p>Ruby C bindings to the excellent Yajl JSON stream-based parser library.

Security Fix(es):

yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf-&amp;gt;alloc into a small heap chunk. These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer. Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. This vulnerability mostly impacts process availability. Maintainers believe exploitation for arbitrary code execution is unlikely. A patch is available and anticipated to be part of yajl-ruby version 1.4.2. As a workaround, avoid passing large inputs to YAJL.(CVE-2022-24795)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12258-1</id>
    <title>openSUSE-SU-2024:12258-1 — libyajl-devel-2.1.0-6.1 on GA media</title>
    <updated>2026-10-03T16:52:30.873433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libyajl-devel-2.1.0-6.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12258-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2063</id>
    <title>RHSA-2024:2063 — Red Hat Security Advisory: yajl security update</title>
    <updated>2026-10-03T16:52:30.873450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>yajl: heap-based buffer overflow when handling large inputs due to an integer overflow yajl: Memory leak in yajl_tree_parse function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1746-1</id>
    <title>SUSE-SU-2022:1746-1 — Security update for libyajl</title>
    <updated>2026-10-03T16:52:30.873469+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libyajl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1746-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24795</id>
    <title>UBUNTU-CVE-2022-24795</title>
    <updated>2026-10-03T16:52:30.873484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: yajl, Ubuntu:Pro:16.04:LTS: yajl, Ubuntu:16.04:LTS: argyll, Ubuntu:16.04:LTS: burp, Ubuntu:16.04:LTS: collada2gltf, Ubuntu:16.04:LTS: icinga2, Ubuntu:Pro:16.04:LTS: libbson, Ubuntu:16.04:LTS: lnav, Ubuntu:16.04:LTS: php-mongodb, Ubuntu:16.04:LTS: r-cran-jsonlite and 53 more</p>
<p>yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. The reallocation logic at `yajl_buf.c#L64` may result in the `need` 32bit integer wrapping to 0 when `need` approaches a value of 0x80000000 (i.e. ~2GB of data), which results in a reallocation of buf-&gt;alloc into a small heap chunk. These integers are declared as `size_t` in the 2.x branch of `yajl`, which practically prevents the issue from triggering on 64bit platforms, however this does not preclude this issue triggering on 32bit builds on which `size_t` is a 32bit integer. Subsequent population of this under-allocated heap chunk is based on the original buffer size, leading to heap memory corruption. This vulnerability mostly impacts process availability. Maintainers believe exploitation for arbitrary code execution is unlikely. A patch is available and anticipated to be part of yajl-ruby version 1.4.2. As a workaround, avoid passing large inputs to YAJL.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0001</id>
    <title>WID-SEC-W-2025-0001 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:52:30.873582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter oder lokaler Angreifer kann mehrere Schwachstellen in IBM DB2 on Cloud Pak for Data ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0001"/>
  </entry>
</feed>
