Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94449.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94449
Upstream
Published
2026-07-30T17:16:33Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-54522 affecting package rubygem-msgpack 1.7.2-1
Details

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmemlast, rmemend, and rmemowner stale after msgpackbuffershift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and a second MessagePack::Buffer to alias the page and disclose or corrupt cross-buffer data. This issue is fixed in version 1.8.2.

References

Affected packages

Azure Linux:3 / rubygem-msgpack

Package

Name
rubygem-msgpack
Purl
pkg:rpm/azure-linux/rubygem-msgpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.7.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94449.json"