logo

Open source programming language R patches gnarly arbitrary code exec flaw

ID: fd4dc6f4-24e7-5bee-965c-1847c4f47762

STIX ID: report--fd4dc6f4-24e7-5bee-965c-1847c4f47762

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-05-01

Date Updated: 2026-04-26

Author: Matthew Connatser

...
...

A critical deserialization vulnerability (CVE-2024-27322, preliminary CVSS 8.8) in R allowed arbitrary code execution when loading crafted RDS files or malicious R packages, risking data loss, exfiltration, or system compromise and posing supply-chain attack vectors against CRAN; R 4.4.0 patched the flaw, and researchers published a proof-of-concept while noting exploitation complexity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.