Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82902.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-82902
Upstream
Published
2026-04-06T20:16:27Z
Modified
2026-08-28T17:47:56Z
Summary
CVE-2026-35201 affecting package rubygem-rdiscount for versions less than 2.2.7.4-1
Details

Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than INT_MAX are truncated to a signed int before entering the native parser, allowing the parser to read past the end of the supplied buffer and crash the process. This vulnerability is fixed in 2.2.7.4.

References

Affected packages

Azure Linux:3 / rubygem-rdiscount

Package

Name
rubygem-rdiscount
Purl
pkg:rpm/azure-linux/rubygem-rdiscount

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.7.4-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82902.json"