Ubuntu alert USN-8478-1 (ruby2.7, ruby3.0, ruby3.2, ruby3.3)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8478-1] Ruby vulnerabilities | |
| Date: | Tue, 30 Jun 2026 16:43:58 +0000 | |
| Message-ID: | <E1webZ0-00033C-39@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8478-1 June 29, 2025 ruby2.7, ruby3.0, ruby3.2, ruby3.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Ruby could allow unintended access to network services. Software Description: - ruby3.3: Object-oriented scripting language - ruby3.2: Object-oriented scripting language - ruby3.0: Object-oriented scripting language - ruby2.7: Object-oriented scripting language Details: It was discovered that Ruby's Net::IMAP library did not properly verify that TLS encryption was started after issuing a STARTTLS command. A remote attacker could use this to perform a machine-in-the-middle attack and silently bypass TLS encryption. (CVE-2026-42246) It was discovered that Ruby's Net::IMAP library did not validate string arguments passed to certain commands. A remote attacker could use this to inject arbitrary IMAP commands. (CVE-2026-42257) It was discovered that Ruby's Net::IMAP library was vulnerable to a denial of service attack when authenticating with SCRAM-SHA1 or SCRAM-SHA256. A hostile server could send a very large iteration count value to cause excessive computation in the client. This issue only affected ruby3.3. (CVE-2026-42256) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libruby3.3 3.3.8-2ubuntu3.1 ruby3.3 3.3.8-2ubuntu3.1 Ubuntu 24.04 LTS libruby3.2 3.2.3-1ubuntu0.24.04.8 ruby3.2 3.2.3-1ubuntu0.24.04.8 Ubuntu 22.04 LTS libruby3.0 3.0.2-7ubuntu2.13 ruby3.0 3.0.2-7ubuntu2.13 Ubuntu 20.04 LTS libruby2.7 2.7.0-5ubuntu1.18+esm5 Available with Ubuntu Pro ruby2.7 2.7.0-5ubuntu1.18+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8478-1 CVE-2026-42246, CVE-2026-42256, CVE-2026-42257 Package Information: https://launchpad.net/ubuntu/+source/ruby3.3/3.3.8-2ubunt... https://launchpad.net/ubuntu/+source/ruby3.2/3.2.3-1ubunt... https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubunt...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpCWkkACgkQcpJm3tlz hgFw3hAAkZCMGt/4lb2YFbm+2F0cCpkaACzILnpz1kPV2b7C7RFzJeHP5hBQ2LlN HngQLhk+UM3qL3bEbQmtsGdAjvG2eNCHGr1AAaMrFPsYeG9h7AstE/QMqROhoXKa uYAfUlndLjq4jgD8DAcLWpiPvoyDLhZsX9QSroy5qyR3WBryo2CaLA3V/OBbsLQo qQfFykkUfTsm1OJKQ0S/enehvktZ90MtEXSIwbM5YumO7B31BjKkdcCXS36E9rcl NEsC3m6CxswxkN7lRI1AZ70lyZPQgiMu3w+RNYlmUIXlJtcdNcx6hw6uYA6XrNeQ HAej0wQz5UwOA9Ng1gkh7mws6lbvJ8H4vZHhZ3tkRx1a7HKmNGLMOxGglzgRC9Il 9EbLid2dO50Uyv7iQ8okFV9VyGDwDkzDQo1v0Ra9JTUHh08e0CkF3SY2O0zIm9ZE 0tFzYVYN/685FKyAKuGFSMjFAQNMX4Kv4k31UYvqQQhqBvH85YC1kzzOh2Krjn3Y cjG9PcIq9x9/2pw5Cw3yWeaEP9ORZp/ox/T/p/KS7V+bBR9u7nABxTSPosHoamJZ 0FFTAYyg3nHII2un8CdaxqCq6kV8DOOLcnrfucvNeU/pYQZ7AxyMToMclQJi1326 2TJ+35u8RSvykVJwu94nBTVBAFig7+ZzKUG2iCNPMpQqWKG/VT8= =z9oW -----END PGP SIGNATURE-----
