Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-20606

Опубликовано: 17 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-20606: ruby4.0 security update (IMPORTANT)

[4.0.3-35]

  • Fix Net::IMAP ResponseReader quadratic complexity vulnerability (CVE-2026-42245) Includes core fix plus additional performance optimizations Resolves: RHEL-181675
  • Fix Net::IMAP STARTTLS stripping vulnerability (CVE-2026-42246) Resolves: RHEL-181767
  • Fix Net::IMAP command injection vulnerability via unvalidated Symbol arguments (CVE-2026-42258) Resolves: RHEL-181793

[4.0.3-34]

  • Upgrade to Ruby 4.0.3. Resolves: RHEL-171239
  • Fix ERB: Arbitrary code execution via bypass (CVE-2026-41316) Resolves: RHEL-170910
  • Fix JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210) Resolves: RHEL-173457

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

ruby4.0

4.0.3-35.el10_2

ruby4.0-devel

4.0.3-35.el10_2

ruby4.0-doc

4.0.3-35.el10_2

ruby4.0-rubygem-mysql2

0.5.7-35.el10_2

ruby4.0-rubygem-pg

1.6.3-35.el10_2

Oracle Linux x86_64

ruby4.0

4.0.3-35.el10_2

ruby4.0-devel

4.0.3-35.el10_2

ruby4.0-doc

4.0.3-35.el10_2

ruby4.0-rubygem-mysql2

0.5.7-35.el10_2

ruby4.0-rubygem-pg

1.6.3-35.el10_2

Связанные CVE

Связанные уязвимости

rocky
около 2 месяцев назад

Important: ruby4.0 security update

rocky
2 месяца назад

Important: ruby:4.0 security update

oracle-oval
около 1 месяца назад

ELSA-2026-20596: ruby:4.0 security update (IMPORTANT)

CVSS3: 9.1
ubuntu
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
redhat
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.