elsa-2026-33577
oracle_linuxruby [4.0.3-33] - Fix Net::IMAP ResponseReader quadratic complexity vulnerability. (CVE-2026-42245) Resolves: RHEL-181690 - Fix Net::IMAP STARTTLS stripping vulnerability. (CVE-2026-42246) Resolves: RHEL-181771 - Fix Net::IMAP command injection vulnerability via unvalidated Symbol arguments. (CVE-2026-42258) Resolves: RHEL-181803 [4.0.3-32] - Upgrade to Ruby 4.0.3. Resolves: RHEL-171933 - Fix ERB: Arbitrary code execution via deserialization bypass (CVE-2026-41316) Resolves: RHEL-171258 - Fix JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210) Resolves: RHEL-173458 rubygem-mysql2 [0.5.7-1] - Upgrade to mysql2 0.5.7. Related: RHEL-142278 rubygem-pg [1.6.3-1] - Upgrade to pg 1.6.3 Related: RHEL-142278
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-42245",
"CVE-2026-42246",
"CVE-2026-42258"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "ruby\n[4.0.3-33]\n- Fix Net::IMAP ResponseReader quadratic complexity vulnerability. (CVE-2026-42245)\n Resolves: RHEL-181690\n- Fix Net::IMAP STARTTLS stripping vulnerability. (CVE-2026-42246)\n Resolves: RHEL-181771\n- Fix Net::IMAP command injection vulnerability via unvalidated Symbol arguments. (CVE-2026-42258)\n Resolves: RHEL-181803\n\n[4.0.3-32]\n- Upgrade to Ruby 4.0.3.\n Resolves: RHEL-171933\n- Fix ERB: Arbitrary code execution via deserialization bypass\n (CVE-2026-41316)\n Resolves: RHEL-171258\n- Fix JSON: Denial of Service or Information Disclosure via format string injection\n (CVE-2026-33210)\n Resolves: RHEL-173458\n\nrubygem-mysql2\n[0.5.7-1]\n- Upgrade to mysql2 0.5.7.\n Related: RHEL-142278\n\nrubygem-pg\n[1.6.3-1]\n- Upgrade to pg 1.6.3\n Related: RHEL-142278",
"id": "ELSA-2026-33577",
"ovalId": "oval:com.oracle.elsa:def:202633577",
"source": "oracle_linux",
"title": "ELSA-2026-33577: ruby:4.0 security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-33577.html"
}