elsa-2026-20596

oracle_linux
Description

ruby [4.0.3-32] - Upgrade to Ruby 4.0.3. Resolves: RHEL-171933 - Fix ERB: Arbitrary code execution via deserialization bypass (CVE-2026-41316) Resolves: RHEL-171258 - Fix JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210) Resolves: RHEL-173458 rubygem-mysql2 [0.5.7-1] - Upgrade to mysql2 0.5.7. Related: RHEL-142278 rubygem-pg [1.6.3-1] - Upgrade to pg 1.6.3 Related: RHEL-142278

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-33210",
    "CVE-2026-41316"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "ruby\n[4.0.3-32]\n- Upgrade to Ruby 4.0.3.\n  Resolves: RHEL-171933\n- Fix ERB: Arbitrary code execution via deserialization bypass\n (CVE-2026-41316)\n  Resolves: RHEL-171258\n- Fix JSON: Denial of Service or Information Disclosure via format string injection\n (CVE-2026-33210)\n Resolves: RHEL-173458\n\nrubygem-mysql2\n[0.5.7-1]\n- Upgrade to mysql2 0.5.7.\n  Related: RHEL-142278\n\nrubygem-pg\n[1.6.3-1]\n- Upgrade to pg 1.6.3\n  Related: RHEL-142278",
  "id": "ELSA-2026-20596",
  "ovalId": "oval:com.oracle.elsa:def:202620596",
  "source": "oracle_linux",
  "title": "ELSA-2026-20596:  ruby:4.0 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-20596.html"
}
View JSON API Download JSON