elsa-2026-33515

oracle_linux
Description

ruby [3.3.10-7] - Fix DoS via crafted IMAP responses in net-imap. (CVE-2026-42245) Resolves: RHEL-181682 - Fix information disclosure via MITM attack bypassing TLS in net-imap. (CVE-2026-42246) Resolves: RHEL-181759 - Fix command injection via Symbol arguments in net-imap. (CVE-2026-42258) Resolves: RHEL-181791 rubygem-abrt [0.4.0-1] - Update to abrt 0.4.0. Resolves: rhbz#1842476 rubygem-mysql2 [0.5.5-1] - Upgrade to mysql2 0.5.5. Related: RHEL-17090 rubygem-pg [1.5.4-1] - Upgrade to pg 1.5.4. Related: RHEL-17090

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-42245",
    "CVE-2026-42246",
    "CVE-2026-42258"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "ruby\n[3.3.10-7]\n- Fix DoS via crafted IMAP responses in net-imap. (CVE-2026-42245)\n  Resolves: RHEL-181682\n- Fix information disclosure via MITM attack bypassing TLS in net-imap.\n  (CVE-2026-42246)\n  Resolves: RHEL-181759\n- Fix command injection via Symbol arguments in net-imap. (CVE-2026-42258)\n  Resolves: RHEL-181791\n\nrubygem-abrt\n[0.4.0-1]\n- Update to abrt 0.4.0.\n  Resolves: rhbz#1842476\n\nrubygem-mysql2\n[0.5.5-1]\n- Upgrade to mysql2 0.5.5.\n  Related: RHEL-17090\n\nrubygem-pg\n[1.5.4-1]\n- Upgrade to pg 1.5.4.\n  Related: RHEL-17090",
  "id": "ELSA-2026-33515",
  "ovalId": "oval:com.oracle.elsa:def:202633515",
  "source": "oracle_linux",
  "title": "ELSA-2026-33515:  ruby:3.3 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-33515.html"
}
View JSON API Download JSON