Описание
ELSA-2026-33540: ruby4.0 security update (IMPORTANT)
[4.0.3-35]
- Fix Net::IMAP ResponseReader quadratic complexity vulnerability (CVE-2026-42245) Includes core fix plus additional performance optimizations Resolves: RHEL-181675
- Fix Net::IMAP STARTTLS stripping vulnerability (CVE-2026-42246) Resolves: RHEL-181767
- Fix Net::IMAP command injection vulnerability via unvalidated Symbol arguments (CVE-2026-42258) Resolves: RHEL-181793
[4.0.3-34]
- Upgrade to Ruby 4.0.3. Resolves: RHEL-171239
- Fix ERB: Arbitrary code execution via bypass (CVE-2026-41316) Resolves: RHEL-170910
- Fix JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210) Resolves: RHEL-173457
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
ruby4.0
4.0.3-35.el10_2
ruby4.0-devel
4.0.3-35.el10_2
ruby4.0-doc
4.0.3-35.el10_2
ruby4.0-rubygem-mysql2
0.5.7-35.el10_2
ruby4.0-rubygem-pg
1.6.3-35.el10_2
Oracle Linux x86_64
ruby4.0
4.0.3-35.el10_2
ruby4.0-devel
4.0.3-35.el10_2
ruby4.0-doc
4.0.3-35.el10_2
ruby4.0-rubygem-mysql2
0.5.7-35.el10_2
ruby4.0-rubygem-pg
1.6.3-35.el10_2