<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:15:37 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>EUVD-2026-331730</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331730</link>
      <description>EUVD-2026-331730</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331730</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54500</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54500</link>
      <description>&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The interned bytes can surface to the caller, disclosing process stack memory. In ext/oj/intern.c, form_attr() handles the long-key path by allocating a heap buffer, `b`, populating it with the attribute name, and then freeing it — but it passed the uninitialized stack buffer buf (not b) to rb_intern3(). rb_intern3 therefore reads len + 1 bytes of uninitialized stack memory. When the key length is &amp;gt;= 256, it also reads out of bounds past the 256-byte buf. The resulting bytes are interned and can reach the caller via the produced Symbol or via the EncodingError message raised on invalid UTF-8, leaking process stack contents. This issue has been fixed in version 3.17.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The interned bytes can surface to the caller, disclosing process stack memory. In ext/oj/intern.c, form_attr() handles the long-key path by allocating a heap buffer, `b`, populating it with the attribute name, and then freeing it — but it passed the uninitialized stack buffer buf (not b) to rb_intern3(). rb_intern3 therefore reads len + 1 bytes of uninitialized stack memory. When the key length is &amp;gt;= 256, it also reads out of bounds past the 256-byte buf. The resulting bytes are interned and can reach the caller via the produced Symbol or via the EncodingError message raised on invalid UTF-8, leaking process stack contents. This issue has been fixed in version 3.17.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54500</guid>
    </item>
    <item>
      <title>GHSA-fm7p-mprw-wjm9 — Oj: intern.c form_attr (uninitialized stack read)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fm7p-mprw-wjm9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oj&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Oj.load` in `:object` mode reads uninitialized stack memory (and, for long
keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes
or longer. The interned bytes can surface to the caller, disclosing process
stack memory.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `ext/oj/intern.c`, `form_attr()` handles the long-key path by allocating a
heap buffer `b`, populating it with the attribute name, and then freeing it —
but it passed the **uninitialized stack buffer `buf`** (not `b`) to
`rb_intern3()`:&lt;/p&gt;
&lt;p&gt;```c
static VALUE form_attr(const char *str, size_t len) {
    char buf[256];
    if (sizeof(buf) - 2 &amp;lt;= len) {        // long-key path (len &amp;gt;= 254)
        char *b = OJ_R_ALLOC_N(char, len + 2);
        // ... b is filled correctly ...
        id = rb_intern3(buf, len + 1, oj_utf8_encoding);   // BUG: reads `buf`
        OJ_R_FREE(b);
        return id;
    }
    // ...
}
```&lt;/p&gt;
&lt;p&gt;`rb_intern3` therefore reads `len + 1` bytes of uninitialized stack memory.
When the key length is &amp;gt;= 256, it also reads out of bounds past the 256-byte
`buf` (CWE-125). The resulting bytes are interned and can reach the caller via
the produced Symbol or via the `EncodingError` message raised on invalid
UTF-8, leaking process stack contents.&lt;/p&gt;
&lt;p&gt;This is the same defect previously fixed in `ext/oj/usual.c`; `intern.c` held
a duplicated copy of `form_attr` that was missed.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;```ruby
require &amp;#39;oj&amp;#39;
key  = &amp;#34;A&amp;#34; * 300
json = %Q[{&amp;#34;^o&amp;#34;:&amp;#34;Object&amp;#34;,&amp;#34;#{key}&amp;#34;:1}]
Oj.load(json, mode: :object)
```&lt;/p&gt;
&lt;p&gt;O…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oj&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Oj.load` in `:object` mode reads uninitialized stack memory (and, for long
keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes
or longer. The interned bytes can surface to the caller, disclosing process
stack memory.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `ext/oj/intern.c`, `form_attr()` handles the long-key path by allocating a
heap buffer `b`, populating it with the attribute name, and then freeing it —
but it passed the **uninitialized stack buffer `buf`** (not `b`) to
`rb_intern3()`:&lt;/p&gt;
&lt;p&gt;```c
static VALUE form_attr(const char *str, size_t len) {
    char buf[256];
    if (sizeof(buf) - 2 &amp;lt;= len) {        // long-key path (len &amp;gt;= 254)
        char *b = OJ_R_ALLOC_N(char, len + 2);
        // ... b is filled correctly ...
        id = rb_intern3(buf, len + 1, oj_utf8_encoding);   // BUG: reads `buf`
        OJ_R_FREE(b);
        return id;
    }
    // ...
}
```&lt;/p&gt;
&lt;p&gt;`rb_intern3` therefore reads `len + 1` bytes of uninitialized stack memory.
When the key length is &amp;gt;= 256, it also reads out of bounds past the 256-byte
`buf` (CWE-125). The resulting bytes are interned and can reach the caller via
the produced Symbol or via the `EncodingError` message raised on invalid
UTF-8, leaking process stack contents.&lt;/p&gt;
&lt;p&gt;This is the same defect previously fixed in `ext/oj/usual.c`; `intern.c` held
a duplicated copy of `form_attr` that was missed.&lt;/p&gt;
&lt;p&gt;### Proof of Concept&lt;/p&gt;
&lt;p&gt;```ruby
require &amp;#39;oj&amp;#39;
key  = &amp;#34;A&amp;#34; * 300
json = %Q[{&amp;#34;^o&amp;#34;:&amp;#34;Object&amp;#34;,&amp;#34;#{key}&amp;#34;:1}]
Oj.load(json, mode: :object)
```&lt;/p&gt;
&lt;p&gt;O…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fm7p-mprw-wjm9</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54500</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj&lt;/p&gt;
&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The interned bytes can surface to the caller, disclosing process stack memory. In ext/oj/intern.c, form_attr() handles the long-key path by allocating a heap buffer, `b`, populating it with the attribute name, and then freeing it — but it passed the uninitialized stack buffer buf (not b) to rb_intern3(). rb_intern3 therefore reads len + 1 bytes of uninitialized stack memory. When the key length is &amp;gt;= 256, it also reads out of bounds past the 256-byte buf. The resulting bytes are interned and can reach the caller via the produced Symbol or via the EncodingError message raised on invalid UTF-8, leaking process stack contents. This issue has been fixed in version 3.17.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj&lt;/p&gt;
&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The interned bytes can surface to the caller, disclosing process stack memory. In ext/oj/intern.c, form_attr() handles the long-key path by allocating a heap buffer, `b`, populating it with the attribute name, and then freeing it — but it passed the uninitialized stack buffer buf (not b) to rb_intern3(). rb_intern3 therefore reads len + 1 bytes of uninitialized stack memory. When the key length is &amp;gt;= 256, it also reads out of bounds past the 256-byte buf. The resulting bytes are interned and can reach the caller via the produced Symbol or via the EncodingError message raised on invalid UTF-8, leaking process stack contents. This issue has been fixed in version 3.17.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54500</guid>
    </item>
  </channel>
</rss>
