#1143948 ruby-json: CVE-2026-71847

Package:
src:ruby-json
Source:
src:ruby-json
Submitter:
Salvatore Bonaccorso
Date:
2026-08-10 01:05:03 UTC
Severity:
normal
Tags:
#1143948#5
Date:
2026-08-08 18:42:58 UTC
From:
To:
Hi,

The following vulnerability was published for ruby-json.

CVE-2026-71847[0]:
| Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until
| 2.21.2, Ruby's JSON native C extension clears the consumed
| JSON::ResumableParser input buffer but leaves state.start,
| state.cursor, and state.end pointing into released storage. When
| partial_value reconstructs an incomplete object containing duplicate
| keys, the duplicate-key warning path calls cursor_position, which
| dereferences those stale pointers. This results in a heap-use-after-
| free and can terminate the Ruby process. An attacker who can supply
| JSON stream data to an application using JSON::ResumableParser may
| cause process termination when the application calls partial_value
| on incomplete attacker-controlled input containing duplicate object
| keys. This issue has been fixed in version 2.21.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-71847
https://www.cve.org/CVERecord?id=CVE-2026-71847
[1] https://github.com/ruby/json/security/advisories/GHSA-9hj4-r449-hfvc
[2] https://github.com/ruby/json/commit/2c332bfe2bfb0e754da07e2a0310ef106bf46482

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143948#8
Date:
2026-08-10 00:37:25 UTC
From:
To:
Hello,

Bug #1143948 in ruby-json reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/ruby-team/ruby-json/-/commit/fddf94786a9d1481832cb21cc8dc3652883346b1

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143948

#1143948#15
Date:
2026-08-10 01:04:18 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
ruby-json, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143948@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Quigley <tsimonq2@debian.org> (supplier of updated ruby-json package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 09 Aug 2026 19:36:44 -0500
Source: ruby-json
Architecture: source
Version: 2.21.2+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org>
Changed-By: Simon Quigley <tsimonq2@debian.org>
Closes: 1143948
Changes:
 ruby-json (2.21.2+dfsg-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release (Closes: #1143948).
Checksums-Sha1:
 dc29234f23860005360d7d5faa5aaae620417ac4 2164 ruby-json_2.21.2+dfsg-1.dsc
 98c619b5da9241056d4f9b4ef6f51b5ef2ae7529 605584 ruby-json_2.21.2+dfsg.orig.tar.xz
 155646d02e79d9a07d1d0e7c0b872fed1f18f54d 8120 ruby-json_2.21.2+dfsg-1.debian.tar.xz
 c998c7db7a3dac6d5f5a54cfe64183389a2a6c6a 7600 ruby-json_2.21.2+dfsg-1_source.buildinfo
Checksums-Sha256:
 580b2ce3a90d24f00a229afba67dbfcc8076135078dab0d3949776455578c746 2164 ruby-json_2.21.2+dfsg-1.dsc
 6a3389b17377fea25092bfc23cd3283ae28176c8914dd0b6b3478c6bf5f4f718 605584 ruby-json_2.21.2+dfsg.orig.tar.xz
 dd4d34a463359b2085d11deac51e51d97c89fec7e6e29d29b4703e22098280d9 8120 ruby-json_2.21.2+dfsg-1.debian.tar.xz
 1e32b878abe2cca2bd3e0c63b2dd39ebb9ed67918cbf0e0e005cf61784a29ca5 7600 ruby-json_2.21.2+dfsg-1_source.buildinfo
Files:
 01c32e44d8c6f35d08079e44ec3bc3ac 2164 ruby optional ruby-json_2.21.2+dfsg-1.dsc
 694260ff4a09c3e402dcf3577d628026 605584 ruby optional ruby-json_2.21.2+dfsg.orig.tar.xz
 c28a1e1df1019cb5d0518cd2a6d015ad 8120 ruby optional ruby-json_2.21.2+dfsg-1.debian.tar.xz
 5cc32c8973e8d744a2d17d844d31e1bd 7600 ruby optional ruby-json_2.21.2+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmp5HUAACgkQ4n8s+EWM
L6R2fw//bJAk/spLjxBfLxVEu3872KPKKi/drnlMFYu6zN8EcduYjDPCsVLXobRD
3FU02Dcdf2MK38LHvNx5BMcG8whfnQM2LFFsBx83iAEmRAo62ds7+cmJtu3dPw2Y
yRFNEOx9Yl9e8Rt/9xyx0TbrhGrUWvcg6FctGDooJwDCd3yFRIu1lIO6oqKjsZwR
g1nIxyzKFs2nU3QeeAtvz1vNhfSSXCjA9YxdQZUEqBwkijZoLq5yudLlUMAwYRqG
PN/1pRGWk4f69cZbTVgzIkiU/gaVg1/K8oLKcy7L6KImbLwnULRP2piG1w5H5N+R
m8x00UN8Ytgmml7UfIbmofI7vipVRhUTYhWUf+k1Mgnskz+errZtOmDgE12dvFbq
+VOab/wLG5t0A2HG4E4wsWwhVaJLrQ0RQVIZ+tneoGQa3YoZHECCbkqyoLf79RUh
YicOwA/8hHNAI8EmJs+cFZt12IVim2AdebDeqU+79pv/RxsRzBVEkQ4kKHL0fKP4
Z3POuUIsV+9V8rnbfbhWAhhD0m2NbIeQZw+DW7hBTYLUljmPkNcjRGrK5pIhGYJC
lFICkvwf5LoTqHlRodAOQ7QJqMdWvwQu6OcHNqDolRh4t4TUGMGQEYlg7pz9mh1q
wPFhsmaO85X9LbGqZTUrWpSEuFz/Fk3Vhq+d5U4rqZRf5Olc3Pw=
=z/Uj
-----END PGP SIGNATURE-----