Skip to content

Commit 536fa7c

Browse files
authored
Merge pull request #1202 from jasnow/ghsa-syncbot-2026-08-08-10_01_04
GHSA/SYNC: One new json advisory @simi - Thanks for reviewing and approving my PR.
2 parents 3642742 + f4b8f93 commit 536fa7c

1 file changed

Lines changed: 92 additions & 0 deletions

File tree

‎gems/json/CVE-2026-71847.yml‎

Lines changed: 92 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,92 @@
1+
---
2+
gem: json
3+
cve: 2026-71847
4+
ghsa: 9hj4-r449-hfvc
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-71847
6+
title: Ruby JSON - JSON::ResumableParser#partial_value dereferences
7+
a freed input buffer and crashes on truncated duplicate-key streams
8+
date: 2026-08-07
9+
description: |
10+
### Summary
11+
12+
Ruby's JSON native C extension clears the consumed `JSON::ResumableParser`
13+
input buffer but leaves `state.start`, `state.cursor`, and `state.end`
14+
pointing into released storage.
15+
16+
When `partial_value` reconstructs an incomplete object containing
17+
duplicate keys, the duplicate-key warning path calls `cursor_position`,
18+
which dereferences those stale pointers. This results in a
19+
heap-use-after-free and can terminate the Ruby process.
20+
21+
An attacker who can supply JSON stream data to an application using
22+
`JSON::ResumableParser` may cause process termination when the
23+
application calls `partial_value` on incomplete attacker-controlled
24+
input containing duplicate object keys.
25+
26+
The issue was reproduced in the native C extension from the official
27+
RubyGems releases:
28+
29+
* JSON 2.20.0
30+
* JSON 2.21.0
31+
* JSON 2.21.1
32+
33+
The attached evidence demonstrates:
34+
35+
* an AddressSanitizer-confirmed heap-use-after-free;
36+
* a native `SIGSEGV` using the official JSON 2.21.1 RubyGem;
37+
* an end-to-end loopback TCP attacker/victim reproduction;
38+
* four differential controls;
39+
* successful execution after applying a tested patch control.
40+
41+
This was originally reported privately through Ruby's HackerOne program
42+
as report `#3867755`. A Ruby maintainer independently confirmed
43+
reproduction of the ASan failure and requested that further
44+
coordination continue through this private advisory.
45+
46+
No code execution or information disclosure is claimed.
47+
48+
### Impact
49+
50+
This is a use-after-free that can result in native Ruby process termination.
51+
52+
An attacker must be able to supply JSON stream data to an application that:
53+
54+
1. uses `JSON::ResumableParser`;
55+
2. processes attacker-controlled streaming input;
56+
3. calls `partial_value` after parsing an incomplete document
57+
containing duplicate object keys.
58+
59+
In network-facing deployments meeting these conditions, an attacker
60+
can cause process termination and denial of service.
61+
62+
The release-build crash was reproduced consistently in the tested
63+
Linux environment. The AddressSanitizer result confirms the underlying
64+
heap-use-after-free independently of normal allocator behavior.
65+
66+
The demonstrated impact is:
67+
68+
```text
69+
Denial of service through native process termination
70+
```
71+
72+
No confidentiality impact, integrity impact, arbitrary code execution,
73+
or information disclosure is claimed.
74+
cvss_v4: 8.7
75+
unaffected_versions:
76+
- "< 2.20.0"
77+
patched_versions:
78+
- ">= 2.21.2"
79+
related:
80+
url:
81+
- https://nvd.nist.gov/vuln/detail/CVE-2026-71847
82+
- https://rubygems.org/gems/json/versions/2.21.2
83+
- https://github.com/ruby/json/blob/master/CHANGES.md#2026-07-31-2212
84+
- https://github.com/ruby/json/releases/tag/v2.21.2
85+
- https://advisories.gitlab.com/gem/json/CVE-2026-71847
86+
- https://osv.dev/vulnerability/GHSA-9hj4-r449-hfvc
87+
- https://github.com/ruby/json/security/advisories/GHSA-9hj4-r449-hfvc
88+
- https://github.com/advisories/GHSA-9hj4-r449-hfvc
89+
notes: |
90+
- "Low" severity in global GHSA URL.
91+
- cvss_v4 from nvd.nist.gov URL.
92+
- Watch for Ruby's HackerOne #3867755.

0 commit comments

Comments
 (0)