Описание
ELSA-2026-20614: ruby:3.3 security update (IMPORTANT)
ruby [3.3.10-6]
- Fix arbitrary code execution via deserialization bypass in ERB. (CVE-2026-41316) Resolves: RHEL-171247
rubygem-abrt [0.4.0-1]
- Update to abrt 0.4.0. Resolves: rhbz#1842476
rubygem-mysql2 [0.5.5-1]
- Upgrade to mysql2 0.5.5. Related: RHEL-17090
rubygem-pg [1.5.4-1]
- Upgrade to pg 1.5.4. Related: RHEL-17090
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
Module ruby:3.3 is enabled
ruby
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-bundled-gems
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-default-gems
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-devel
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-doc
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-libs
3.3.10-6.module+el8.10.0+90896+16c7234c
rubygem-abrt
0.4.0-1.module+el8.10.0+90287+d51aa4ed
rubygem-abrt-doc
0.4.0-1.module+el8.10.0+90287+d51aa4ed
rubygem-bigdecimal
3.1.5-6.module+el8.10.0+90896+16c7234c
rubygem-bundler
2.5.22-6.module+el8.10.0+90896+16c7234c
rubygem-io-console
0.7.1-6.module+el8.10.0+90896+16c7234c
rubygem-irb
1.13.1-6.module+el8.10.0+90896+16c7234c
rubygem-json
2.7.2-6.module+el8.10.0+90896+16c7234c
rubygem-minitest
5.20.0-6.module+el8.10.0+90896+16c7234c
rubygem-mysql2
0.5.5-1.module+el8.10.0+90287+d51aa4ed
rubygem-mysql2-doc
0.5.5-1.module+el8.10.0+90287+d51aa4ed
rubygem-pg
1.5.4-1.module+el8.10.0+90287+d51aa4ed
rubygem-pg-doc
1.5.4-1.module+el8.10.0+90287+d51aa4ed
rubygem-power_assert
2.0.3-6.module+el8.10.0+90896+16c7234c
rubygem-psych
5.1.2-6.module+el8.10.0+90896+16c7234c
rubygem-racc
1.7.3-6.module+el8.10.0+90896+16c7234c
rubygem-rake
13.1.0-6.module+el8.10.0+90896+16c7234c
rubygem-rbs
3.4.0-6.module+el8.10.0+90896+16c7234c
rubygem-rdoc
6.6.3.1-6.module+el8.10.0+90896+16c7234c
rubygem-rexml
3.4.4-6.module+el8.10.0+90896+16c7234c
rubygem-rss
0.3.1-6.module+el8.10.0+90896+16c7234c
rubygem-test-unit
3.6.1-6.module+el8.10.0+90896+16c7234c
rubygem-typeprof
0.21.9-6.module+el8.10.0+90896+16c7234c
rubygems
3.5.22-6.module+el8.10.0+90896+16c7234c
rubygems-devel
3.5.22-6.module+el8.10.0+90896+16c7234c
Oracle Linux x86_64
Module ruby:3.3 is enabled
ruby
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-bundled-gems
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-default-gems
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-devel
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-doc
3.3.10-6.module+el8.10.0+90896+16c7234c
ruby-libs
3.3.10-6.module+el8.10.0+90896+16c7234c
rubygem-abrt
0.4.0-1.module+el8.10.0+90287+d51aa4ed
rubygem-abrt-doc
0.4.0-1.module+el8.10.0+90287+d51aa4ed
rubygem-bigdecimal
3.1.5-6.module+el8.10.0+90896+16c7234c
rubygem-bundler
2.5.22-6.module+el8.10.0+90896+16c7234c
rubygem-io-console
0.7.1-6.module+el8.10.0+90896+16c7234c
rubygem-irb
1.13.1-6.module+el8.10.0+90896+16c7234c
rubygem-json
2.7.2-6.module+el8.10.0+90896+16c7234c
rubygem-minitest
5.20.0-6.module+el8.10.0+90896+16c7234c
rubygem-mysql2
0.5.5-1.module+el8.10.0+90287+d51aa4ed
rubygem-mysql2-doc
0.5.5-1.module+el8.10.0+90287+d51aa4ed
rubygem-pg
1.5.4-1.module+el8.10.0+90287+d51aa4ed
rubygem-pg-doc
1.5.4-1.module+el8.10.0+90287+d51aa4ed
rubygem-power_assert
2.0.3-6.module+el8.10.0+90896+16c7234c
rubygem-psych
5.1.2-6.module+el8.10.0+90896+16c7234c
rubygem-racc
1.7.3-6.module+el8.10.0+90896+16c7234c
rubygem-rake
13.1.0-6.module+el8.10.0+90896+16c7234c
rubygem-rbs
3.4.0-6.module+el8.10.0+90896+16c7234c
rubygem-rdoc
6.6.3.1-6.module+el8.10.0+90896+16c7234c
rubygem-rexml
3.4.4-6.module+el8.10.0+90896+16c7234c
rubygem-rss
0.3.1-6.module+el8.10.0+90896+16c7234c
rubygem-test-unit
3.6.1-6.module+el8.10.0+90896+16c7234c
rubygem-typeprof
0.21.9-6.module+el8.10.0+90896+16c7234c
rubygems
3.5.22-6.module+el8.10.0+90896+16c7234c
rubygems-devel
3.5.22-6.module+el8.10.0+90896+16c7234c
Связанные CVE
Связанные уязвимости
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evaluate `@src` via `eval()` were not given the same guard: `ERB#def_method`, `ERB#def_module`, and `ERB#def_class`. An attacker who can trigger `Marshal.load` on untrusted data in a Ruby application that has `erb` loaded can use `ERB#def_module` (zero-arg, default parameters) as a code execution sink, bypassing the `@_init` protection entirely. ERB 4.0.3.1, 4.0.4.1, 6.0.1.1, and 6.0.4 patch the issue.
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was ...