Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian: cJSON Important Input Sanitization Issue DSA-6001-1 CVE-2025-57052

debian
Calendar Grey September 14, 2025
Debian Logo
cJSON identified to possess inadequate input validation, resulting in potential buffer overflow vulnerabilities. Update advised.
It was discovered that cJSON, an ultralightweight JSON parser, performed insufficient input sanitising, which could result in out-of-bounds memory access

Summary

It was discovered that cJSON, an ultralightweight JSON parser, performed
insufficient input sanitising, which could result in out-of-bounds
memory access.

For the oldstable distribution (bookworm), this problem has been fixed
in version 1.7.15-1+deb12u4.

For the stable distribution (trixie), this problem has been fixed in
version 1.7.18-3.1+deb13u1.

We recommend that you upgrade your cjson packages.

For the detailed security status of cjson please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/cjson

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: cjson
CVE ID: CVE-2025-57052

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here