<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 23:05:17 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>EUVD-2026-331858</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-331858</link>
      <description>EUVD-2026-331858</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-331858</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54502</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54502</link>
      <description>&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-based buffer overflow when a large :indent value is provided by the developer. fill_indent in dump.h calls memset(indent_str, &amp;#39; &amp;#39;, (size_t)opts-&amp;gt;indent) without validating the size. When opts-&amp;gt;indent is set to INT_MAX (2,147,483,647), the (size_t) cast preserves the large value and memset writes 2 GB into the stack-allocated out buffer (4,184 bytes), corrupting the stack and crashing the process. This issue has been fixed in version 3.17.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-based buffer overflow when a large :indent value is provided by the developer. fill_indent in dump.h calls memset(indent_str, &amp;#39; &amp;#39;, (size_t)opts-&amp;gt;indent) without validating the size. When opts-&amp;gt;indent is set to INT_MAX (2,147,483,647), the (size_t) cast preserves the large value and memset writes 2 GB into the stack-allocated out buffer (4,184 bytes), corrupting the stack and crashing the process. This issue has been fixed in version 3.17.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54502</guid>
    </item>
    <item>
      <title>GHSA-3v45-f3vh-wg7m — Oj: Stack Buffer Overflow in Oj.dump via Large Indent</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3v45-f3vh-wg7m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oj&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Oj.dump` is vulnerable to a stack-based buffer overflow when a large `:indent` value is provided by the developer. `fill_indent` in `dump.h` calls `memset(indent_str, &amp;#39; &amp;#39;, (size_t)opts-&amp;gt;indent)` without validating the size. When `opts-&amp;gt;indent` is set to `INT_MAX` (2,147,483,647), the `(size_t)` cast preserves the large value and `memset` writes 2 GB into the stack-allocated `out` buffer (4,184 bytes), corrupting the stack and crashing the process.&lt;/p&gt;
&lt;p&gt;### Version&lt;/p&gt;
&lt;p&gt;- **Software**: oj gem
- **Affected**: all versions with `ext/oj/dump.h`
- **Latest tested**: 3.17.1 (confirmed present)&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`ext/oj/dump.h`, line 77:&lt;/p&gt;
&lt;p&gt;```c
static void fill_indent(Out out, int depth) {
    if (0 &amp;lt; out-&amp;gt;opts-&amp;gt;indent) {
        size_t len = (size_t)(out-&amp;gt;opts-&amp;gt;indent * depth);
        // ...
        memset(out-&amp;gt;buf + ..., &amp;#39; &amp;#39;, len);  // len = 2147483647 * depth
```&lt;/p&gt;
&lt;p&gt;The `indent` option is accepted as a plain Ruby integer and stored as `int` without range validation. Multiplying by `depth` can produce a value larger than any stack or heap buffer.&lt;/p&gt;
&lt;p&gt;ASAN report:
```
==69820==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fd1fc201278
WRITE of size 2147483647 at 0x7fd1fc201278 thread T0
    #0 memset
    #1 fill_indent  /ext/oj/dump.h:77
    #2 dump_array   /ext/oj/dump_compat.c:165
    #3 oj_dump_obj_to_json_using_params  /ext/oj/dump.c:818
    #4 dump_body    /ext/oj/oj.c:1429
    #5 dump         /ext/oj/oj.c:1480
Address is in stack of thread T0 at offset 4728 in fra…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: oj&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`Oj.dump` is vulnerable to a stack-based buffer overflow when a large `:indent` value is provided by the developer. `fill_indent` in `dump.h` calls `memset(indent_str, &amp;#39; &amp;#39;, (size_t)opts-&amp;gt;indent)` without validating the size. When `opts-&amp;gt;indent` is set to `INT_MAX` (2,147,483,647), the `(size_t)` cast preserves the large value and `memset` writes 2 GB into the stack-allocated `out` buffer (4,184 bytes), corrupting the stack and crashing the process.&lt;/p&gt;
&lt;p&gt;### Version&lt;/p&gt;
&lt;p&gt;- **Software**: oj gem
- **Affected**: all versions with `ext/oj/dump.h`
- **Latest tested**: 3.17.1 (confirmed present)&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`ext/oj/dump.h`, line 77:&lt;/p&gt;
&lt;p&gt;```c
static void fill_indent(Out out, int depth) {
    if (0 &amp;lt; out-&amp;gt;opts-&amp;gt;indent) {
        size_t len = (size_t)(out-&amp;gt;opts-&amp;gt;indent * depth);
        // ...
        memset(out-&amp;gt;buf + ..., &amp;#39; &amp;#39;, len);  // len = 2147483647 * depth
```&lt;/p&gt;
&lt;p&gt;The `indent` option is accepted as a plain Ruby integer and stored as `int` without range validation. Multiplying by `depth` can produce a value larger than any stack or heap buffer.&lt;/p&gt;
&lt;p&gt;ASAN report:
```
==69820==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7fd1fc201278
WRITE of size 2147483647 at 0x7fd1fc201278 thread T0
    #0 memset
    #1 fill_indent  /ext/oj/dump.h:77
    #2 dump_array   /ext/oj/dump_compat.c:165
    #3 oj_dump_obj_to_json_using_params  /ext/oj/dump.c:818
    #4 dump_body    /ext/oj/oj.c:1429
    #5 dump         /ext/oj/oj.c:1480
Address is in stack of thread T0 at offset 4728 in fra…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3v45-f3vh-wg7m</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54502</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj&lt;/p&gt;
&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-based buffer overflow when a large :indent value is provided by the developer. fill_indent in dump.h calls memset(indent_str, &amp;#39; &amp;#39;, (size_t)opts-&amp;gt;indent) without validating the size. When opts-&amp;gt;indent is set to INT_MAX (2,147,483,647), the (size_t) cast preserves the large value and memset writes 2 GB into the stack-allocated out buffer (4,184 bytes), corrupting the stack and crashing the process. This issue has been fixed in version 3.17.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-oj, Ubuntu:16.04:LTS: ruby-oj, Ubuntu:18.04:LTS: ruby-oj, Ubuntu:20.04:LTS: ruby-oj, Ubuntu:22.04:LTS: ruby-oj, Ubuntu:24.04:LTS: ruby-oj, Ubuntu:25.10: ruby-oj, Ubuntu:26.04:LTS: ruby-oj&lt;/p&gt;
&lt;p&gt;Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-based buffer overflow when a large :indent value is provided by the developer. fill_indent in dump.h calls memset(indent_str, &amp;#39; &amp;#39;, (size_t)opts-&amp;gt;indent) without validating the size. When opts-&amp;gt;indent is set to INT_MAX (2,147,483,647), the (size_t) cast preserves the large value and memset writes 2 GB into the stack-allocated out buffer (4,184 bytes), corrupting the stack and crashing the process. This issue has been fixed in version 3.17.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54502</guid>
    </item>
  </channel>
</rss>
