DEBIAN-CVE-2026-88358

Source
https://security-tracker.debian.org/tracker/CVE-2026-88358
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88358.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-88358
Upstream
Published
2026-09-24T16:17:13Z
Modified
2026-09-25T12:00:07Z
Summary
[none]
Details

simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or object can cause json_iterator::walk_document() to access buf[len] after the input buffer has been exhausted. This results in a heap out-of-bounds read and may cause application termination, leading to denial of service.

References

Affected packages

Debian:12 / simdjson

Package

Name
simdjson
Purl
pkg:deb/debian/simdjson?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.1-1
3.2.1-1~exp1
3.2.1-1
3.2.3-1
3.6.0-1~exp1
3.6.3-1~exp1
3.6.3-1
3.6.4-1
3.9.4-1~exp1
3.10.1-1~exp1
3.10.1-1
3.12.0-1
3.12.0-2
3.12.2-1
3.12.3-1
3.13.0-1
3.13.0-1.1
4.*
4.2.3-1
4.2.4-1
4.3.1-1
4.3.1-2
4.3.1-4
4.3.1-5
4.3.1+really4.2.4-1
4.3.1+really4.3.1-1
4.5.0-1
4.6.0-1
4.6.3-1
4.6.4-1
4.6.5-1
4.6.6-1
4.6.7-1
4.6.8-1
4.6.11-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88358.json"

Debian:13 / simdjson

Package

Name
simdjson
Purl
pkg:deb/debian/simdjson?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.12.3-1
3.13.0-1
3.13.0-1.1
4.*
4.2.3-1
4.2.4-1
4.3.1-1
4.3.1-2
4.3.1-4
4.3.1-5
4.3.1+really4.2.4-1
4.3.1+really4.3.1-1
4.5.0-1
4.6.0-1
4.6.3-1
4.6.4-1
4.6.5-1
4.6.6-1
4.6.7-1
4.6.8-1
4.6.11-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88358.json"

Debian:14 / simdjson

Package

Name
simdjson
Purl
pkg:deb/debian/simdjson?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.12.3-1
3.13.0-1
3.13.0-1.1
4.*
4.2.3-1
4.2.4-1
4.3.1-1
4.3.1-2
4.3.1-4
4.3.1-5
4.3.1+really4.2.4-1
4.3.1+really4.3.1-1
4.5.0-1
4.6.0-1
4.6.3-1
4.6.4-1
4.6.5-1
4.6.6-1
4.6.7-1
4.6.8-1
4.6.11-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88358.json"