elsa-2026-20606
oracle_linux[4.0.3-35] - Fix Net::IMAP ResponseReader quadratic complexity vulnerability (CVE-2026-42245) Includes core fix plus additional performance optimizations Resolves: RHEL-181675 - Fix Net::IMAP STARTTLS stripping vulnerability (CVE-2026-42246) Resolves: RHEL-181767 - Fix Net::IMAP command injection vulnerability via unvalidated Symbol arguments (CVE-2026-42258) Resolves: RHEL-181793 [4.0.3-34] - Upgrade to Ruby 4.0.3. Resolves: RHEL-171239 - Fix ERB: Arbitrary code execution via bypass (CVE-2026-41316) Resolves: RHEL-170910 - Fix JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210) Resolves: RHEL-173457
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-33210",
"CVE-2026-41316"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[4.0.3-35]\n- Fix Net::IMAP ResponseReader quadratic complexity vulnerability (CVE-2026-42245)\n Includes core fix plus additional performance optimizations\n Resolves: RHEL-181675\n- Fix Net::IMAP STARTTLS stripping vulnerability (CVE-2026-42246)\n Resolves: RHEL-181767\n- Fix Net::IMAP command injection vulnerability via unvalidated Symbol arguments (CVE-2026-42258)\n Resolves: RHEL-181793\n\n[4.0.3-34]\n- Upgrade to Ruby 4.0.3.\n Resolves: RHEL-171239\n- Fix ERB: Arbitrary code execution via bypass\n (CVE-2026-41316)\n Resolves: RHEL-170910\n- Fix JSON: Denial of Service or Information Disclosure via format string injection\n (CVE-2026-33210)\n Resolves: RHEL-173457",
"id": "ELSA-2026-20606",
"ovalId": "oval:com.oracle.elsa:def:202620606",
"source": "oracle_linux",
"title": "ELSA-2026-20606: ruby4.0 security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-20606.html"
}