Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:20606

Опубликовано: 04 июн. 2026
Источник: rocky
Оценка: Important

Описание

Important: ruby4.0 security update

Ruby is the interpreted scripting language for quick and easy object-oriented programming. It has many features to process text files and to do system management tasks (as in Perl). It is simple, straight-forward, and extensible.

Security Fix(es):

  • ruby/json: Ruby JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210)

  • erb: ERB: Arbitrary code execution via deserialization bypass (CVE-2026-41316)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
ruby4.0-rubygem-pgaarch6434.el10_2ruby4.0-rubygem-pg-1.6.3-34.el10_2.aarch64.rpm
ruby4.0-rubygem-mysql2aarch6434.el10_2ruby4.0-rubygem-mysql2-0.5.7-34.el10_2.aarch64.rpm
ruby4.0-develaarch6434.el10_2ruby4.0-devel-4.0.3-34.el10_2.aarch64.rpm
ruby4.0aarch6434.el10_2ruby4.0-4.0.3-34.el10_2.aarch64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

rocky
2 месяца назад

Important: ruby:4.0 security update

oracle-oval
16 дней назад

ELSA-2026-20606: ruby4.0 security update (IMPORTANT)

oracle-oval
около 1 месяца назад

ELSA-2026-20596: ruby:4.0 security update (IMPORTANT)

CVSS3: 9.1
ubuntu
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.

CVSS3: 9.1
redhat
4 месяца назад

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2.