<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>bitwize music — Security Advisories</title><link>https://www.bitwizemusic.com/security/advisories/</link><description>Vulnerability disclosures by bitwize under the BVE identifier scheme.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 30 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.bitwizemusic.com/security/advisories/index.xml" rel="self" type="application/rss+xml"/><item><title>BVE-2026-0007 — STIGQter: Local Code Execution via Crafted .stigqter Project File + Export HTML (User Interaction Required)</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0007/</link><pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0007/</guid><category>path-traversal</category><category>local-code-execution</category><category>user-interaction</category><category>qt</category><category>systemd</category><category>polyglot</category><description><![CDATA[<p>STIGQter writes per-STIG HTML files using filenames pulled directly from the SQLite STIG.fileName column of the loaded .stigqter project file. Combined with an unescaped variables.HTMLHeader value written into each output file, an attacker who can convince a user to open a crafted .stigqter and click Export HTML can drop attacker-controlled content at attacker-chosen absolute paths — including a polyglot HTML / systemd unit that runs arbitrary code on the next systemctl --user daemon-reload. Fixed upstream on 2026-04-24.</p>
        <p><strong>Status:</strong> Fixed. <strong>Severity:</strong> High. <strong>Vendor:</strong> squinky86 (Jon Hood). <strong>Product:</strong> STIGQter.
        </p><p><strong>CVE:</strong> CVE-2026-42881</p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0007/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0008 — Pending</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0008/</link><pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0008/</guid><description><![CDATA[<p>A vulnerability discovered on 2026-04-27 and submitted to the Zero Day Initiative the same day for coordinated disclosure. Full details will be published here once disclosure is complete.</p>
        <p><strong>Status:</strong> Pending. <strong>Severity:</strong> Critical. 
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0008/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0006 — Pending</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0006/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0006/</guid><category>code-execution</category><category>local</category><description><![CDATA[<p>A local code execution vulnerability discovered on 2026-04-19. It has been reported to the vendor, with a CVE requested on 2026-04-22. Full details will be published here once disclosure is complete.</p>
        <p><strong>Status:</strong> Pending. <strong>Severity:</strong> Critical. 
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0006/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0005 — Pending</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0005/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0005/</guid><category>rce</category><category>unauthenticated</category><description><![CDATA[<p>A critical unauthenticated remote code execution vulnerability discovered on 2026-04-19 and reported to the Zero Day Initiative (ZDI) the same day. Full details will be published here once disclosure is complete.</p>
        <p><strong>Status:</strong> Pending. <strong>Severity:</strong> Critical. 
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0005/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0004 — Pending</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0004/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0004/</guid><category>rce</category><category>unauthenticated</category><description><![CDATA[<p>A critical unauthenticated remote code execution vulnerability discovered on 2026-04-19 and reported to the Zero Day Initiative (ZDI) the same day. Full details will be published here once disclosure is complete.</p>
        <p><strong>Status:</strong> Pending. <strong>Severity:</strong> Critical. 
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0004/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0002 — ok_json: heap buffer overread in UTF-8 validation</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0002/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0002/</guid><category>heap-buffer-overread</category><category>json-parser</category><category>memory-safety</category><category>utf-8</category><description><![CDATA[<p>A heap buffer overread in ok_json&#39;s UTF-8 validator. A multi-byte UTF-8 lead byte at the end of input causes the validator to read continuation bytes past the end of the caller-supplied buffer. Fixed upstream on 2026-04-14.</p>
        <p><strong>Status:</strong> Fixed. <strong>Severity:</strong> High. <strong>Vendor:</strong> ionux. <strong>Product:</strong> ok_json.
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0002/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0003 — ok_json: heap buffer overread in true/false/null keyword matching</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0003/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0003/</guid><category>heap-buffer-overread</category><category>json-parser</category><category>memory-safety</category><description><![CDATA[<p>A heap buffer overread in ok_json&#39;s keyword matcher. Input shorter than the expected keyword (`true`, `false`, `null`) causes `okj_match` to read past the end of the caller-supplied buffer. Fixed upstream on 2026-04-14.</p>
        <p><strong>Status:</strong> Fixed. <strong>Severity:</strong> High. <strong>Vendor:</strong> ionux. <strong>Product:</strong> ok_json.
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0003/">View advisory</a></p>
      ]]></description></item><item><title>BVE-2026-0001 — ok_json: heap buffer overread in \uXXXX escape parsing</title><link>https://www.bitwizemusic.com/security/advisories/bve-2026-0001/</link><pubDate>Wed, 22 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.bitwizemusic.com/security/advisories/bve-2026-0001/</guid><category>heap-buffer-overread</category><category>json-parser</category><category>memory-safety</category><description><![CDATA[<p>A heap buffer overread in ok_json&#39;s `\uXXXX` escape parser. A truncated `\u` escape at the end of input causes the parser to read past the end of the caller-supplied buffer while consuming hex digits. Fixed upstream on 2026-04-14.</p>
        <p><strong>Status:</strong> Fixed. <strong>Severity:</strong> High. <strong>Vendor:</strong> ionux. <strong>Product:</strong> ok_json.
        </p>
        <p><a href="https://www.bitwizemusic.com/security/advisories/bve-2026-0001/">View advisory</a></p>
      ]]></description></item></channel></rss>