CVE-2024-27322

Public on 2024-04-29
Modified on 2024-05-02
Description
Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.
Severity
Important severity
Important
CVSS v3 Base Score
8.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 R 2024-06-19 ALAS-2024-1940 Fixed
HAQM Linux 2 - R3.4 Extra R 2024-06-28 ALAS2R3.4-2024-001 Fixed
HAQM Linux 2 - R4 Extra R 2024-06-19 ALAS2R4-2024-002 Fixed
HAQM Linux 2023 R 2024-06-06 ALAS2023-2024-638 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NVD CVSSv3 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H