What is CVE-2026-54522?
CVE-2026-54522 is a vulnerability in the MessagePack for Ruby library. Due to improper memory page handling in `MessagePack::Buffer#clear`, stale pointers remain after returning memory to the shared pool. Developers using versions prior to 1.8.2 should urgently update.
Azərbaycanca: CVE-2026-54522 MessagePack for Ruby kitabxanasında aşkarlanmış zəiflikdir. Bu, `MessagePack::Buffer#clear` funksiyasında yaddaş səhifələrinin səhv idarə edilməsi nəticəsində köhnəlmiş göstəricilərin qalmasına səbəb olur. 1.8.2 versiyasından əvvəlki versiyalardan istifadə edən tərtibatçılar təcili olaraq yenilənmə etməlidir.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which versions of MessagePack for Ruby are affected by CVE-2026-54522?
This vulnerability affects versions of the MessagePack for Ruby library prior to 1.8.2.
Which function is the root cause of CVE-2026-54522?
The vulnerability is caused by improper memory page handling in the `MessagePack::Buffer#clear` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.