Use After Free Affecting ruby3.2-fluentd-kubernetes-daemonset-1.19 package, versions <1.19.2.1.1-r7


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-WOLFILATEST-RUBY32FLUENTDKUBERNETESDAEMONSET119-18553577
  • published6 Aug 2026
  • disclosed30 Jul 2026

Introduced: 30 Jul 2026

NewCVE-2026-54522  (opens in a new tab)
CWE-416  (opens in a new tab)

How to fix?

Upgrade Wolfi ruby3.2-fluentd-kubernetes-daemonset-1.19 to version 1.19.2.1.1-r7 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ruby3.2-fluentd-kubernetes-daemonset-1.19 package and not the ruby3.2-fluentd-kubernetes-daemonset-1.19 package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool, allowing a subsequent Buffer#write and a second MessagePack::Buffer to alias the page and disclose or corrupt cross-buffer data. This issue is fixed in version 1.8.2.

CVSS Base Scores

version 3.1