elsa-2026-18030
oracle_linuxruby [3.3.10-6] - Fix arbitrary code execution via deserialization bypass in ERB. (CVE-2026-41316) Resolves: RHEL-171255 [3.3.10-5] - Upgrade to Ruby 3.3.10. Resolves: RHEL-127912 - Fix possible denial of service in resolv gem (CVE-2025-24294) - Fix URI Credential Leakage Bypass previous fixes. (CVE-2025-61594) - Fix REXML denial of service. (CVE-2025-58767) Resolves: RHEL-122015 [3.3.8-4] - Upgrade to Ruby 3.3.8. Resolves: RHEL-68631 - Fix Net::IMAP vulnerable to possible DoS by memory exhaustion. (CVE-2025-25186) - Fix Denial of Service in CGI::Cookie.parse. (CVE-2025-27219) Resolves: RHEL-86109 - Fix userinfo leakage in URI#join, URI#merge and URI#+. (CVE-2025-27221) [3.3.5-3] - Upgrade to Ruby 3.3.5 Resolves: RHEL-55411 - Fix DoS vulnerability in rexml. (CVE-2024-39908) (CVE-2024-41946) (CVE-2024-43398) Resolves: RHEL-57575 Resolves: RHEL-57572 Resolves: RHEL-57068 - Fix REXML DoS when parsing an XML having many specific characters such as whitespace character, ] and ]. (CVE-2024-41123) Resolves: RHEL-57569 - Fix incorrect symlink for rubygem-irb's library. Resolves: RHEL-42646 [3.3.1-2] - Upgrade to Ruby 3.3.1. Resolves: RHEL-33976 - Fix buffer overread vulnerability in StringIO. (CVE-2024-27280) Resolves: RHEL-34130 - Fix RCE vulnerability with .rdoc_options in RDoc. (CVE-2024-27281) Resolves: RHEL-34122 - Fix Arbitrary memory address read vulnerability with Regex search. (CVE-2024-27282) Resolves: RHEL-33872 rubygem-mysql2 [0.5.5-3] - Disable tests on the 32bit platforms ix86. Related: RHEL-80222 [0.5.5-2] - Adapt tests to openssl 3.2 Resolves: RHEL-80222 [0.5.5-1] - Upgrade to mysql2 0.5.5. Related: RHEL-17089 rubygem-pg [-1.5.4-2] - Fix encoding issue in spec suite. Resolves: RHEL-159200
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-41316"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "ruby\n[3.3.10-6]\n- Fix arbitrary code execution via deserialization bypass in ERB. (CVE-2026-41316)\n Resolves: RHEL-171255\n\n[3.3.10-5]\n- Upgrade to Ruby 3.3.10.\n Resolves: RHEL-127912\n- Fix possible denial of service in resolv gem (CVE-2025-24294)\n- Fix URI Credential Leakage Bypass previous fixes. (CVE-2025-61594)\n- Fix REXML denial of service. (CVE-2025-58767)\n Resolves: RHEL-122015\n\n[3.3.8-4]\n- Upgrade to Ruby 3.3.8.\n Resolves: RHEL-68631\n- Fix Net::IMAP vulnerable to possible DoS by memory exhaustion. (CVE-2025-25186)\n- Fix Denial of Service in CGI::Cookie.parse. (CVE-2025-27219)\n Resolves: RHEL-86109\n- Fix userinfo leakage in URI#join, URI#merge and URI#+. (CVE-2025-27221)\n\n[3.3.5-3]\n- Upgrade to Ruby 3.3.5\n Resolves: RHEL-55411\n- Fix DoS vulnerability in rexml.\n (CVE-2024-39908)\n (CVE-2024-41946)\n (CVE-2024-43398)\n Resolves: RHEL-57575\n Resolves: RHEL-57572\n Resolves: RHEL-57068\n- Fix REXML DoS when parsing an XML having many specific characters such as\n whitespace character, ] and ].\n (CVE-2024-41123)\n Resolves: RHEL-57569\n- Fix incorrect symlink for rubygem-irb's library.\n Resolves: RHEL-42646\n\n[3.3.1-2]\n- Upgrade to Ruby 3.3.1.\n Resolves: RHEL-33976\n- Fix buffer overread vulnerability in StringIO.\n (CVE-2024-27280)\n Resolves: RHEL-34130\n- Fix RCE vulnerability with .rdoc_options in RDoc.\n (CVE-2024-27281)\n Resolves: RHEL-34122\n- Fix Arbitrary memory address read vulnerability with Regex search.\n (CVE-2024-27282)\n Resolves: RHEL-33872\n\nrubygem-mysql2\n[0.5.5-3]\n- Disable tests on the 32bit platforms ix86.\n Related: RHEL-80222\n\n[0.5.5-2]\n- Adapt tests to openssl 3.2\n Resolves: RHEL-80222\n\n[0.5.5-1]\n- Upgrade to mysql2 0.5.5.\n Related: RHEL-17089\n\nrubygem-pg\n[-1.5.4-2]\n- Fix encoding issue in spec suite.\n Resolves: RHEL-159200",
"id": "ELSA-2026-18030",
"ovalId": "oval:com.oracle.elsa:def:202618030",
"source": "oracle_linux",
"title": "ELSA-2026-18030: ruby:3.3 security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-18030.html"
}