<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:53:49.064470+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-05T18:53:49.067950+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331730</id>
    <title>EUVD-2026-331730</title>
    <updated>2026-10-05T18:53:49.067987+00:00</updated>
    <content>EUVD-2026-331730</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331730"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54500</id>
    <title>fkie_cve-2026-54500</title>
    <updated>2026-10-05T18:53:49.068002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The interned bytes can surface to the caller, disclosing process stack memory. In ext/oj/intern.c, form_attr() handles the long-key path by allocating a heap buffer, `b`, populating it with the attribute name, and then freeing it — but it passed the uninitialized stack buffer buf (not b) to rb_intern3(). rb_intern3 therefore reads len + 1 bytes of uninitialized stack memory. When the key length is &gt;= 256, it also reads out of bounds past the 256-byte buf. The resulting bytes are interned and can reach the caller via the produced Symbol or via the EncodingError message raised on invalid UTF-8, leaking process stack contents. This issue has been fixed in version 3.17.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fm7p-mprw-wjm9</id>
    <title>GHSA-fm7p-mprw-wjm9 — Oj: intern.c form_attr (uninitialized stack read)</title>
    <updated>2026-10-05T18:53:49.068039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: oj</p>
<p>### Summary</p>
<p>`Oj.load` in `:object` mode reads uninitialized stack memory (and, for long
keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes
or longer. The interned bytes can surface to the caller, disclosing process
stack memory.</p>
<p>### Details</p>
<p>In `ext/oj/intern.c`, `form_attr()` handles the long-key path by allocating a
heap buffer `b`, populating it with the attribute name, and then freeing it —
but it passed the **uninitialized stack buffer `buf`** (not `b`) to
`rb_intern3()`:</p>
<p>```c
static VALUE form_attr(const char *str, size_t len) {
    char buf[256];
    if (sizeof(buf) - 2 &lt;= len) {        // long-key path (len &gt;= 254)
        char *b = OJ_R_ALLOC_N(char, len + 2);
        // ... b is filled correctly ...
        id = rb_intern3(buf, len + 1, oj_utf8_encoding);   // BUG: reads `buf`
        OJ_R_FREE(b);
        return id;
    }
    // ...
}
```</p>
<p>`rb_intern3` therefore reads `len + 1` bytes of uninitialized stack memory.
When the key length is &gt;= 256, it also reads out of bounds past the 256-byte
`buf` (CWE-125). The resulting bytes are interned and can reach the caller via
the produced Symbol or via the `EncodingError` message raised on invalid
UTF-8, leaking process stack contents.</p>
<p>This is the same defect previously fixed in `ext/oj/usual.c`; `intern.c` held
a duplicated copy of `form_attr` that was missed.</p>
<p>### Proof of Concept</p>
<p>```ruby
require 'oj'
key  = "A" * 300
json = %Q[{"^o":"Object","#{key}":1}]
Oj.load(json, mode: :object)
```</p>
<p>O…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fm7p-mprw-wjm9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54500</id>
    <title>UBUNTU-CVE-2026-54500</title>
    <updated>2026-10-05T18:53:49.068092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj</p>
<p>Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The interned bytes can surface to the caller, disclosing process stack memory. In ext/oj/intern.c, form_attr() handles the long-key path by allocating a heap buffer, `b`, populating it with the attribute name, and then freeing it — but it passed the uninitialized stack buffer buf (not b) to rb_intern3(). rb_intern3 therefore reads len + 1 bytes of uninitialized stack memory. When the key length is &gt;= 256, it also reads out of bounds past the 256-byte buf. The resulting bytes are interned and can reach the caller via the produced Symbol or via the EncodingError message raised on invalid UTF-8, leaking process stack contents. This issue has been fixed in version 3.17.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54500"/>
  </entry>
</feed>
