Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-20596

Опубликовано: 24 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-20596: ruby:4.0 security update (IMPORTANT)

ruby [4.0.3-32]

  • Upgrade to Ruby 4.0.3. Resolves: RHEL-171933
  • Fix ERB: Arbitrary code execution via deserialization bypass (CVE-2026-41316) Resolves: RHEL-171258
  • Fix JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210) Resolves: RHEL-173458

rubygem-mysql2 [0.5.7-1]

  • Upgrade to mysql2 0.5.7. Related: RHEL-142278

rubygem-pg [1.6.3-1]

  • Upgrade to pg 1.6.3 Related: RHEL-142278

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

Module ruby:4.0 is enabled

ruby

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-bundled-gems

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-default-gems

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-devel

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-doc

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-libs

4.0.3-32.module+el9.8.0+90929+122d8796

rubygem-bigdecimal

4.0.1-32.module+el9.8.0+90929+122d8796

rubygem-bundler

4.0.6-32.module+el9.8.0+90929+122d8796

rubygem-io-console

0.8.2-32.module+el9.8.0+90929+122d8796

rubygem-irb

1.16.0-32.module+el9.8.0+90929+122d8796

rubygem-json

2.18.0-32.module+el9.8.0+90929+122d8796

rubygem-minitest

6.0.0-32.module+el9.8.0+90929+122d8796

rubygem-mysql2

0.5.7-1.module+el9.8.0+90929+122d8796

rubygem-mysql2-doc

0.5.7-1.module+el9.8.0+90929+122d8796

rubygem-pg

1.6.3-1.module+el9.8.0+90929+122d8796

rubygem-pg-doc

1.6.3-1.module+el9.8.0+90929+122d8796

rubygem-power_assert

3.0.1-32.module+el9.8.0+90929+122d8796

rubygem-psych

5.3.1-32.module+el9.8.0+90929+122d8796

rubygem-racc

1.8.1-32.module+el9.8.0+90929+122d8796

rubygem-rake

13.3.1-32.module+el9.8.0+90929+122d8796

rubygem-rbs

3.10.0-32.module+el9.8.0+90929+122d8796

rubygem-rdoc

7.0.3-32.module+el9.8.0+90929+122d8796

rubygem-rexml

3.4.4-32.module+el9.8.0+90929+122d8796

rubygem-rss

0.3.2-32.module+el9.8.0+90929+122d8796

rubygem-test-unit

3.7.5-32.module+el9.8.0+90929+122d8796

rubygem-typeprof

0.31.1-32.module+el9.8.0+90929+122d8796

rubygems

4.0.6-32.module+el9.8.0+90929+122d8796

rubygems-devel

4.0.6-32.module+el9.8.0+90929+122d8796

Oracle Linux x86_64

Module ruby:4.0 is enabled

ruby

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-bundled-gems

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-default-gems

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-devel

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-doc

4.0.3-32.module+el9.8.0+90929+122d8796

ruby-libs

4.0.3-32.module+el9.8.0+90929+122d8796

rubygem-bigdecimal

4.0.1-32.module+el9.8.0+90929+122d8796

rubygem-bundler

4.0.6-32.module+el9.8.0+90929+122d8796

rubygem-io-console

0.8.2-32.module+el9.8.0+90929+122d8796

rubygem-irb

1.16.0-32.module+el9.8.0+90929+122d8796

rubygem-json

2.18.0-32.module+el9.8.0+90929+122d8796

rubygem-minitest

6.0.0-32.module+el9.8.0+90929+122d8796

rubygem-mysql2

0.5.7-1.module+el9.8.0+90929+122d8796

rubygem-mysql2-doc

0.5.7-1.module+el9.8.0+90929+122d8796

rubygem-pg

1.6.3-1.module+el9.8.0+90929+122d8796

rubygem-pg-doc

1.6.3-1.module+el9.8.0+90929+122d8796

rubygem-power_assert

3.0.1-32.module+el9.8.0+90929+122d8796

rubygem-psych

5.3.1-32.module+el9.8.0+90929+122d8796

rubygem-racc

1.8.1-32.module+el9.8.0+90929+122d8796

rubygem-rake

13.3.1-32.module+el9.8.0+90929+122d8796

rubygem-rbs

3.10.0-32.module+el9.8.0+90929+122d8796

rubygem-rdoc

7.0.3-32.module+el9.8.0+90929+122d8796

rubygem-rexml

3.4.4-32.module+el9.8.0+90929+122d8796

rubygem-rss

0.3.2-32.module+el9.8.0+90929+122d8796

rubygem-test-unit

3.7.5-32.module+el9.8.0+90929+122d8796

rubygem-typeprof

0.31.1-32.module+el9.8.0+90929+122d8796

rubygems

4.0.6-32.module+el9.8.0+90929+122d8796

rubygems-devel

4.0.6-32.module+el9.8.0+90929+122d8796

Связанные CVE

Связанные уязвимости

rocky
около 2 месяцев назад

Important: ruby4.0 security update

rocky
2 месяца назад

Important: ruby:4.0 security update

oracle-oval
16 дней назад

ELSA-2026-20606: ruby4.0 security update (IMPORTANT)

CVSS3: 9.1
ubuntu
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
redhat
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.