<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 00:46:02 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>EUVD-2026-331614</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331614</link>
      <description>EUVD-2026-331614</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331614</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54903</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54903</link>
      <description>&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54903</guid>
    </item>
    <item>
      <title>GHSA-475m-ph3x-64gp — Oj: Integer Overflow in Oj.load 2GB String Handling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-475m-ph3x-64gp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oj&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Oj.load` is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in `buf_append_string` (`buf.h:61`) converts the string length to a large negative `size_t`, causing `memcpy` to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory.&lt;/p&gt;
&lt;p&gt;### Version&lt;/p&gt;
&lt;p&gt;- **Software**: oj gem
- **Affected**: all versions with `ext/oj/buf.h` and `ext/oj/parse.c`
- **Latest tested**: 3.17.1 (confirmed present)&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`ext/oj/buf.h`, line 61:&lt;/p&gt;
&lt;p&gt;```c
inline static void buf_append_string(Buf buf, const char *s, size_t slen) {
    // ...
    memcpy(buf-&amp;gt;tail, s, slen);   // slen derived from 32-bit int that wrapped negative
```&lt;/p&gt;
&lt;p&gt;In `parse.c`, escape sequence handling computes the remaining string length as an `int`:&lt;/p&gt;
&lt;p&gt;```c
// parse.c:402 (read_escaped_str)
int  slen = (int)(s - str);   // ← wraps to negative when string &amp;gt; 2 GB
buf_append_string(buf, str, (size_t)slen);  // ← (size_t)(-2147483648) = 0x80000000...
```&lt;/p&gt;
&lt;p&gt;ASAN report:
```
==399019==ERROR: AddressSanitizer: negative-size-param: (size=-2147483648)
    #0 __asan_memcpy
    #1 buf_append_string  /ext/oj/buf.h:61
    #2 read_escaped_str   /ext/oj/parse.c:402
    #3 read_str           /ext/oj/parse.c:542
    #4 oj_parse2          /ext/oj/parse.c:882
    #5 oj_pi_parse        /ext/oj/parse.c:1256
    #6 oj_object_parse    /ext/oj/object.c:701
    #7 load               /ext/oj/oj.c:1259
0x7f5a26ff0801 is located 1 bytes insi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oj&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Oj.load` is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in `buf_append_string` (`buf.h:61`) converts the string length to a large negative `size_t`, causing `memcpy` to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory.&lt;/p&gt;
&lt;p&gt;### Version&lt;/p&gt;
&lt;p&gt;- **Software**: oj gem
- **Affected**: all versions with `ext/oj/buf.h` and `ext/oj/parse.c`
- **Latest tested**: 3.17.1 (confirmed present)&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`ext/oj/buf.h`, line 61:&lt;/p&gt;
&lt;p&gt;```c
inline static void buf_append_string(Buf buf, const char *s, size_t slen) {
    // ...
    memcpy(buf-&amp;gt;tail, s, slen);   // slen derived from 32-bit int that wrapped negative
```&lt;/p&gt;
&lt;p&gt;In `parse.c`, escape sequence handling computes the remaining string length as an `int`:&lt;/p&gt;
&lt;p&gt;```c
// parse.c:402 (read_escaped_str)
int  slen = (int)(s - str);   // ← wraps to negative when string &amp;gt; 2 GB
buf_append_string(buf, str, (size_t)slen);  // ← (size_t)(-2147483648) = 0x80000000...
```&lt;/p&gt;
&lt;p&gt;ASAN report:
```
==399019==ERROR: AddressSanitizer: negative-size-param: (size=-2147483648)
    #0 __asan_memcpy
    #1 buf_append_string  /ext/oj/buf.h:61
    #2 read_escaped_str   /ext/oj/parse.c:402
    #3 read_str           /ext/oj/parse.c:542
    #4 oj_parse2          /ext/oj/parse.c:882
    #5 oj_pi_parse        /ext/oj/parse.c:1256
    #6 oj_object_parse    /ext/oj/object.c:701
    #7 load               /ext/oj/oj.c:1259
0x7f5a26ff0801 is located 1 bytes insi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-475m-ph3x-64gp</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54903</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54903</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj&lt;/p&gt;
&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj&lt;/p&gt;
&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to a large negative size_t, causing memcpy to copy an astronomically large amount of data out of bounds. This crashes the process and can corrupt adjacent heap memory. The issue has been fixed in version 3.17.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54903</guid>
    </item>
  </channel>
</rss>
