Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54522

Опубликовано: 30 июл. 2026
Источник: debian
EPSS Низкий

Описание

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and a second MessagePack::Buffer to alias the page and disclose or corrupt cross-buffer data. This issue is fixed in version 1.8.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-msgpackfixed1.8.3-1package
ruby-msgpackpostponedbookwormpackage
ruby-msgpackpostponedbullseyepackage

Примечания

  • https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938

  • Fixed by: https://github.com/msgpack/msgpack-ruby/commit/5627d71606b565641d2dd501b82aae862f4abe90 (v1.8.2)

EPSS

Процентиль: 3%
0.00136
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
8 дней назад

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and a second MessagePack::Buffer to alias the page and disclose or corrupt cross-buffer data. This issue is fixed in version 1.8.2.

CVSS3: 5.4
nvd
8 дней назад

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and a second MessagePack::Buffer to alias the page and disclose or corrupt cross-buffer data. This issue is fixed in version 1.8.2.

github
8 дней назад

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

EPSS

Процентиль: 3%
0.00136
Низкий