Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-46727

Опубликовано: 22 мая 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-based exploitation is theoretically possible. The attack could, for example, be carried out through a crafted authoritative DNS server or recursive resolver.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.5 (исключая)

EPSS

Процентиль: 38%
0.00478
Низкий

8.1 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-based exploitation is theoretically possible. The attack could, for example, be carried out through a crafted authoritative DNS server or recursive resolver.

CVSS3: 8.1
debian
3 месяца назад

An issue was discovered in Ruby 4 before 4.0.5. A race condition leadi ...

CVSS3: 8.1
github
3 месяца назад

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-based exploitation is theoretically possible. The attack could, for example, be carried out through a crafted authoritative DNS server or recursive resolver.

EPSS

Процентиль: 38%
0.00478
Низкий

8.1 High

CVSS3

Дефекты

CWE-362