R Language Security Update Advisory

Overview

 

We have released an update to address a vulnerability in the R language. users of affected versions are advised to update to the latest version.

 

Affected Products

 

R language versions: 1.4.0 (inclusive) to 4.4.0 (excluded)

 

Resolved Vulnerabilities

 

Deserialization of untrusted data in the R language allows maliciously crafted RDS-formatted files or R packages to execute arbitrary code (CVE-2024-27322)

 

Vulnerability Patches

 

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

R language version: 4.4.0

 

Referenced Sites

 

[1] CVE-2024-27322 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-27322

[2] R Programming Language implementations are vulnerable to arbitrary code execution during deserialization of .rds and .rdx files

https://www.kb.cert.org/vuls/id/238194