Ubuntu alert USN-8515-1 (ruby-addressable)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8515-1] Addressable vulnerability | |
| Date: | Tue, 07 Jul 2026 16:57:19 +0000 | |
| Message-ID: | <E1wh96l-00058J-W0@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8515-1 July 07, 2026 ruby-addressable vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Addressable could be made to consume resources and cause a denial of service if it received specially crafted input. Software Description: - ruby-addressable: Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library Details: It was discovered that Addressable incorrectly handled certain URI templates, generating regular expressions vulnerable to catastrophic backtracking. An attacker could use this issue to craft a URI that, when matched against a vulnerable template, causes excessive resource consumption, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS ruby-addressable 2.8.7-2ubuntu0.26.04.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS ruby-addressable 2.8.5-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS ruby-addressable 2.8.0-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS ruby-addressable 2.7.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS ruby-addressable 2.5.2-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS ruby-addressable 2.3.8-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8515-1 CVE-2026-35611
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpNK6gACgkQcpJm3tlz hgFoNA//SaFjJOmaZYsq9fKbw43EkwjmLCvQBDE1y6mq6pmEK+dFcY7npTEB9wEZ we/cn9CMK3tpxCqQ4fkBotEU6Gw8amZDComCZpMuewD4OMwC2dm4HLhJbFuR2wyB jRA0T8AJa1CUi6eVnglYVB7eqXXkK5tA1CLsfvQJy8eYiab+IjNjK7gIzXJMuVIS bMv9J6hgL1M77g+OZHbZ22dDENr17VAjk2J7sKcR3ZR+W5pkO2TICKleVz50ljNe hYFjQg/LASvo/RC3hoAbIY8R0me594F4mdUxk7jOZDj+8CX3M1JRn/4KuUe9Dr9G KniYqKYeGuPIQuxj7phKX8x3NpFKLcdg9R5ysLi9O7RdH9Rr/YokBL/K+CzLUR3b xicbMN3ZLZa2YtKcPyVOzn3hThXGaftCTkbdSQpUBoPEXirNpzZgps9z4mE3sMzr 9A64eLtDNmz+x8L6lfBWhjp3xJTSRDC/pop0AKKZ9BLjI3CmLSL0707Nltkje0o0 InJ2WnU6r31gNl4Nd19xH17puDo9jv7irOjFeu17zzT+ikC2rmD3FwIQp6/1K9wB CgAeW4p6WO+52tTFXrioVcsPUExZMPnYI7f/h3BpUTI6m/0rV0Xk3kKUekuP3Xp1 ccDFxlpVNYNVUcK59kyHeZuC9Wjj5JhmPH4Z0vdHgv5ulWU2ucg= =7NlM -----END PGP SIGNATURE-----
