Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
Rocky Linux 8: pandoc table parsing flaw
RLSA-2022:5597
Summary
A security update is available for Rocky Linux 8 to fix a bug in the pandoc software that converts text formats. This bug could potentially allow an attacker to execute malicious code. We recommend updating your system to the latest version of pandoc to fix this issue.
What to do
- Update pandoc to version 0:2.0.6-6.el8_6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Rocky Linux:8 | – | pandoc |
< 0:2.0.6-6.el8_6 Fix: upgrade to 0:2.0.6-6.el8_6
|
Original title
Important: pandoc security update
Original description
Pandoc is a markdown/markup conversion tool. The version of pandoc in Rocky Linux 8 CRB uses cmark-gfm (GitHub's extended version of the C reference implementation of CommonMark) for parts of its conversion. The update, fixes CVE-2022-24724: an integer overflow in cmark-gfm's table row parsing which may lead to heap memory corruption when parsing tables with more than UINT16_MAX columns.
Security Fix(es):
* cmark-gfm: possible RCE due to integer overflow (CVE-2022-24724)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Security Fix(es):
* cmark-gfm: possible RCE due to integer overflow (CVE-2022-24724)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
osv CVSS3.1
8.8
- https://errata.rockylinux.org/RLSA-2022:5597 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2060662 Third Party Advisory
Published: 28 Jun 2026 · Updated: 28 Jun 2026 · First seen: 28 Jun 2026