cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. https://github.com/DaveGamble/cJSON/issues/839
Created cjson tracking bugs for this issue: Affects: epel-all [bug 2277269] Affects: fedora-all [bug 2277270] Created mmc tracking bugs for this issue: Affects: fedora-all [bug 2277271]
Nice with all the tracking bugs, but a fix has been available since April 26 2024, and a new release containing the fix since May 13. https://github.com/DaveGamble/cJSON/releases/tag/v1.7.18 Why hasn't a new release of the packages been triggered?
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2025:9022 https://access.redhat.com/errata/RHSA-2025:9022