Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ubuntu Security

USN-8189-1: RapidJSON vulnerability

An integer overflow vulnerability (CVE-2024-39684, CVSS 7.8 HIGH) in RapidJSON allows a remote attacker to cause a crash or privilege escalation by supplying a specially crafted JSON file. The vulnerability affects the `rapidjson-dev` package across multiple Ubuntu LTS releases, including 16.04, 18.04, 20.04, 22.04, and 24.04. The fix is available via Ubuntu Pro's Extended Security Maintenance (ESM) for each affected release, with specific patched package versions listed in the USN.
Read Full Article →

Ubuntu Security Notices USN-8189-1 USN-8189-1: RapidJSON vulnerability Publication date 20 April 2026 Overview RapidJSON could be made to crash or run programs as an administrator if it opened a specially crafted file. Releases 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages rapidjson - A fast JSON parser/generator for C++ Details It was discovered that RapidJSON did not properly protect against integer overflows in certain instances when parsing JSON text. A remote attacker could possibly use this issue to craft a malicious JSON file, that when read by RapidJSON, would lead to an elevation of privilege, resulting in the potential disclosure of sensitive information. It was discovered that RapidJSON did not properly protect against integer overflows in certain instances when parsing JSON text. A remote attacker could possibly use this issue to craft a malicious JSON file, that when read by RapidJSON, would lead to an elevation of privilege, resulting in the potential disclosure of sensitive information. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 24.04 LTS noble rapidjson-dev – 1.1.0+dfsg2-7.2ubuntu0.1~esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 22.04 LTS jammy rapidjson-dev – 1.1.0+dfsg2-7ubuntu0.1~esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 20.04 LTS focal rapidjson-dev – 1.1.0+dfsg2-5ubuntu1+esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 18.04 LTS bionic rapidjson-dev – 1.1.0+dfsg2-3ubuntu0.1~esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 16.04 LTS xenial rapidjson-dev – 0.12~git20141031-3ubuntu0.1~esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2024-39684 CVE-2024-39684

Share this article