Ubuntu alert USN-8431-1 (ruby2.3, ruby2.5)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8431-1] Ruby vulnerabilities | |
| Date: | Tue, 16 Jun 2026 10:07:42 +0000 | |
| Message-ID: | <E1wZQhq-0003US-Cy@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8431-1 June 15, 2026 ruby2.3, ruby2.5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Ruby could allow unintended access to network services. Software Description: - ruby2.5: Object-oriented scripting language - ruby2.3: Object-oriented scripting language Details: It was discovered that Ruby's Net::IMAP library did not properly verify that Transport Layer Security (TLS) encryption was started after issuing a STARTTLS command. A remote attacker could possibly use this issue to perform a machine-in-the-middle attack and silently bypass TLS encryption. (CVE-2026-42246) It was also discovered that Ruby's Net::IMAP library did not validate string arguments passed to certain commands. A remote attacker could possibly use this issue to inject arbitrary IMAP commands. (CVE-2026-42257) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libruby2.5 2.5.1-1ubuntu1.16+esm8 Available with Ubuntu Pro ruby2.5 2.5.1-1ubuntu1.16+esm8 Available with Ubuntu Pro Ubuntu 16.04 LTS libruby2.3 2.3.1-2~ubuntu16.04.16+esm14 Available with Ubuntu Pro ruby2.3 2.3.1-2~ubuntu16.04.16+esm14 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8431-1 CVE-2026-42246, CVE-2026-42257
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmowP4EACgkQcpJm3tlz hgFeYQ/+LmiyoWVNZRM/mZopT2EifIqtQ6yJFwNFZ6sf/QEMSNMjqGwEX96ROvca NB7BECxkhSe835Hf++7vMU+oiKGOHW3PEXPSvXo6WWO+EdfFdBI7CUvgAIxes8Pj SqzJ662LtLqJ4PBYf1jMOkNAxWJwSt1zkRY/ILMzCErUtJiWURd2dQFCHfntw8ke qiwQsFt+8LSZY4HStxoPEqAv84doC7irGmnLrvShcMy0NudP4ycwsezv8klFp8yi 4ieb15INzDHc5abnr79E/A2HUQFuZL0HSVq/Iao55b27DMkb6nklCw8l6PQ+N7Ei tQt7amnvkuCG2dbvZD9MEVdk0yV6gMRFAeLKFQA/ZLrSRfVi2EdQWn2Iu5rlxy1n dpL2E7cKkjRyjhq7fi7p7YlMDhWGA2cXF2l64sd+lWeitKos+GSuuWk2QHaC67Sy sk1j/wMiOiFZNt3J2/3XQGl7dCLcJ4d9jhE+y7pvL3QM2ouNofwa2SFi8+to8znY jN7OcKJIO2/r+pgM6euhoPNNt1aGKK7+8HZtbqY2/dLbAlQJXy5MON21YtEZhgH7 qqzp4sd6x7g7GPGO2z5Z07GQY7JI1xVajk890E/nFpSEL9drTIQFl2qqZVgj2ecW 80Gis5XYwacflnruaXx6lPKhjrdUgFGWNaQQJL5tpn9uwPy2f/Y= =BuLL -----END PGP SIGNATURE-----
