<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T05:45:48.018493+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-09T05:45:48.088645+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331614</id>
    <title>EUVD-2026-331614</title>
    <updated>2026-10-09T05:45:48.088693+00:00</updated>
    <content>EUVD-2026-331614</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331614"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54903</id>
    <title>fkie_cve-2026-54903</title>
    <updated>2026-10-09T05:45:48.088709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-475m-ph3x-64gp</id>
    <title>GHSA-475m-ph3x-64gp — Oj: Integer Overflow in Oj.load 2GB String Handling</title>
    <updated>2026-10-09T05:45:48.088742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: oj</p>
<p>### Summary</p>
<p>`Oj.load` is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in `buf_append_string` (`buf.h:61`) converts the string length to a large negative `size_t`, causing `memcpy` to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory.</p>
<p>### Version</p>
<p>- **Software**: oj gem
- **Affected**: all versions with `ext/oj/buf.h` and `ext/oj/parse.c`
- **Latest tested**: 3.17.1 (confirmed present)</p>
<p>### Details</p>
<p>`ext/oj/buf.h`, line 61:</p>
<p>```c
inline static void buf_append_string(Buf buf, const char *s, size_t slen) {
    // ...
    memcpy(buf-&gt;tail, s, slen);   // slen derived from 32-bit int that wrapped negative
```</p>
<p>In `parse.c`, escape sequence handling computes the remaining string length as an `int`:</p>
<p>```c
// parse.c:402 (read_escaped_str)
int  slen = (int)(s - str);   // ← wraps to negative when string &gt; 2 GB
buf_append_string(buf, str, (size_t)slen);  // ← (size_t)(-2147483648) = 0x80000000...
```</p>
<p>ASAN report:
```
==399019==ERROR: AddressSanitizer: negative-size-param: (size=-2147483648)
    #0 __asan_memcpy
    #1 buf_append_string  /ext/oj/buf.h:61
    #2 read_escaped_str   /ext/oj/parse.c:402
    #3 read_str           /ext/oj/parse.c:542
    #4 oj_parse2          /ext/oj/parse.c:882
    #5 oj_pi_parse        /ext/oj/parse.c:1256
    #6 oj_object_parse    /ext/oj/object.c:701
    #7 load               /ext/oj/oj.c:1259
0x7f5a26ff0801 is located 1 bytes insi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-475m-ph3x-64gp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54903</id>
    <title>UBUNTU-CVE-2026-54903</title>
    <updated>2026-10-09T05:45:48.088791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj</p>
<p>Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54903"/>
  </entry>
</feed>
