AZL-100911

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100911.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-100911
Upstream
Published
2026-09-10T01:16:35Z
Modified
2026-09-14T05:26:59Z
Summary
CVE-2026-87933 affecting package ceph 18.2.2-12
Details

A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.

References

Affected packages

Azure Linux:3 / ceph

Package

Name
ceph
Purl
pkg:rpm/azure-linux/ceph

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
18.2.2-12

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100911.json"