Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18030

Опубликовано: 19 мая 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-18030: ruby:3.3 security update (IMPORTANT)

ruby [3.3.10-6]

  • Fix arbitrary code execution via deserialization bypass in ERB. (CVE-2026-41316) Resolves: RHEL-171255

[3.3.10-5]

  • Upgrade to Ruby 3.3.10. Resolves: RHEL-127912
  • Fix possible denial of service in resolv gem (CVE-2025-24294)
  • Fix URI Credential Leakage Bypass previous fixes. (CVE-2025-61594)
  • Fix REXML denial of service. (CVE-2025-58767) Resolves: RHEL-122015

[3.3.8-4]

  • Upgrade to Ruby 3.3.8. Resolves: RHEL-68631
  • Fix Net::IMAP vulnerable to possible DoS by memory exhaustion. (CVE-2025-25186)
  • Fix Denial of Service in CGI::Cookie.parse. (CVE-2025-27219) Resolves: RHEL-86109
  • Fix userinfo leakage in URI#join, URI#merge and URI#+. (CVE-2025-27221)

[3.3.5-3]

  • Upgrade to Ruby 3.3.5 Resolves: RHEL-55411
  • Fix DoS vulnerability in rexml. (CVE-2024-39908) (CVE-2024-41946) (CVE-2024-43398) Resolves: RHEL-57575 Resolves: RHEL-57572 Resolves: RHEL-57068
  • Fix REXML DoS when parsing an XML having many specific characters such as whitespace character, >] and ]>. (CVE-2024-41123) Resolves: RHEL-57569
  • Fix incorrect symlink for rubygem-irb's library. Resolves: RHEL-42646

[3.3.1-2]

  • Upgrade to Ruby 3.3.1. Resolves: RHEL-33976
  • Fix buffer overread vulnerability in StringIO. (CVE-2024-27280) Resolves: RHEL-34130
  • Fix RCE vulnerability with .rdoc_options in RDoc. (CVE-2024-27281) Resolves: RHEL-34122
  • Fix Arbitrary memory address read vulnerability with Regex search. (CVE-2024-27282) Resolves: RHEL-33872

rubygem-mysql2 [0.5.5-3]

  • Disable tests on the 32bit platforms ix86. Related: RHEL-80222

[0.5.5-2]

  • Adapt tests to openssl 3.2 Resolves: RHEL-80222

[0.5.5-1]

  • Upgrade to mysql2 0.5.5. Related: RHEL-17089

rubygem-pg [-1.5.4-2]

  • Fix encoding issue in spec suite. Resolves: RHEL-159200

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

Module ruby:3.3 is enabled

ruby

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-bundled-gems

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-default-gems

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-devel

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-doc

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-libs

3.3.10-6.module+el9.7.0+90894+66578cbb

rubygem-bigdecimal

3.1.5-6.module+el9.7.0+90894+66578cbb

rubygem-bundler

2.5.22-6.module+el9.7.0+90894+66578cbb

rubygem-io-console

0.7.1-6.module+el9.7.0+90894+66578cbb

rubygem-irb

1.13.1-6.module+el9.7.0+90894+66578cbb

rubygem-json

2.7.2-6.module+el9.7.0+90894+66578cbb

rubygem-minitest

5.20.0-6.module+el9.7.0+90894+66578cbb

rubygem-mysql2

0.5.5-3.module+el9.7.0+90894+66578cbb

rubygem-mysql2-doc

0.5.5-3.module+el9.7.0+90894+66578cbb

rubygem-pg

1.5.4-2.module+el9.7.0+90894+66578cbb

rubygem-pg-doc

1.5.4-2.module+el9.7.0+90894+66578cbb

rubygem-power_assert

2.0.3-6.module+el9.7.0+90894+66578cbb

rubygem-psych

5.1.2-6.module+el9.7.0+90894+66578cbb

rubygem-racc

1.7.3-6.module+el9.7.0+90894+66578cbb

rubygem-rake

13.1.0-6.module+el9.7.0+90894+66578cbb

rubygem-rbs

3.4.0-6.module+el9.7.0+90894+66578cbb

rubygem-rdoc

6.6.3.1-6.module+el9.7.0+90894+66578cbb

rubygem-rexml

3.4.4-6.module+el9.7.0+90894+66578cbb

rubygem-rss

0.3.1-6.module+el9.7.0+90894+66578cbb

rubygem-test-unit

3.6.1-6.module+el9.7.0+90894+66578cbb

rubygem-typeprof

0.21.9-6.module+el9.7.0+90894+66578cbb

rubygems

3.5.22-6.module+el9.7.0+90894+66578cbb

rubygems-devel

3.5.22-6.module+el9.7.0+90894+66578cbb

Oracle Linux x86_64

Module ruby:3.3 is enabled

ruby

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-bundled-gems

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-default-gems

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-devel

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-doc

3.3.10-6.module+el9.7.0+90894+66578cbb

ruby-libs

3.3.10-6.module+el9.7.0+90894+66578cbb

rubygem-bigdecimal

3.1.5-6.module+el9.7.0+90894+66578cbb

rubygem-bundler

2.5.22-6.module+el9.7.0+90894+66578cbb

rubygem-io-console

0.7.1-6.module+el9.7.0+90894+66578cbb

rubygem-irb

1.13.1-6.module+el9.7.0+90894+66578cbb

rubygem-json

2.7.2-6.module+el9.7.0+90894+66578cbb

rubygem-minitest

5.20.0-6.module+el9.7.0+90894+66578cbb

rubygem-mysql2

0.5.5-3.module+el9.7.0+90894+66578cbb

rubygem-mysql2-doc

0.5.5-3.module+el9.7.0+90894+66578cbb

rubygem-pg

1.5.4-2.module+el9.7.0+90894+66578cbb

rubygem-pg-doc

1.5.4-2.module+el9.7.0+90894+66578cbb

rubygem-power_assert

2.0.3-6.module+el9.7.0+90894+66578cbb

rubygem-psych

5.1.2-6.module+el9.7.0+90894+66578cbb

rubygem-racc

1.7.3-6.module+el9.7.0+90894+66578cbb

rubygem-rake

13.1.0-6.module+el9.7.0+90894+66578cbb

rubygem-rbs

3.4.0-6.module+el9.7.0+90894+66578cbb

rubygem-rdoc

6.6.3.1-6.module+el9.7.0+90894+66578cbb

rubygem-rexml

3.4.4-6.module+el9.7.0+90894+66578cbb

rubygem-rss

0.3.1-6.module+el9.7.0+90894+66578cbb

rubygem-test-unit

3.6.1-6.module+el9.7.0+90894+66578cbb

rubygem-typeprof

0.21.9-6.module+el9.7.0+90894+66578cbb

rubygems

3.5.22-6.module+el9.7.0+90894+66578cbb

rubygems-devel

3.5.22-6.module+el9.7.0+90894+66578cbb

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.

CVSS3: 8.1
redhat
3 месяца назад

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.

CVSS3: 8.1
nvd
3 месяца назад

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.

CVSS3: 8.1
debian
3 месяца назад

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was ...

rocky
2 месяца назад

Important: ruby:3.3 security update