CVE-2024-25713: Fedoraproject Fedora

High severity, CVSS 8.6. EPSS: 1.8% chance of exploitation in the next 30 days.

yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)

Affected products

  • Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
  • Ibireme Yyjson: up to and including 0.8.0

Published 2024-02-29. Last modified 2026-06-17.