Ubuntu alert USN-8556-1 (ruby2.3)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8556-1] Ruby vulnerabilities | |
| Date: | Thu, 16 Jul 2026 15:50:23 +0000 | |
| Message-ID: | <E1wkOLv-0004Mp-L8@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8556-1 July 16, 2026 ruby2.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Ruby. Software Description: - ruby2.3: Object-oriented scripting language Details: It was discovered that the Net::IMAP client in Ruby did not properly sanitize Symbol arguments passed to IMAP commands. A remote attacker controlling a malicious IMAP server, or able to influence command arguments, could use this to inject arbitrary IMAP commands via CRLF sequences. (CVE-2026-42258) It was discovered that the Zlib::GzipReader in Ruby did not correctly ensure sufficient buffer capacity in the zstream_buffer_ungets function. An attacker could use this to craft a gzip stream that, when processed, could cause a buffer overflow, resulting in memory corruption and possibly arbitrary code execution. (CVE-2026-27820) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libruby2.3 2.3.1-2~ubuntu16.04.16+esm15 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8556-1 CVE-2026-27820, CVE-2026-42258
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpY/TEACgkQcpJm3tlz hgHi4w/9EJC75nQrs0rvq2PDjmPfW4jhPvIZVYGIVAZwb8m/757svDaoUmFSUk8V wCt64dqgKGKsTO5kBwTaC65pqHwjoolVOo1s5HSmU4h9XvvTJZhSwMq7KayqQEUp KI8NW1Tnz4Vm2OP2zPGZ/p/xa2C7ZPgtScP6q13u+E/JE0RSt9+2SpaKIMu/NED5 SzCKa4qBVFfAFJrF5fOFQELwGzncr65lJl+v5dL6X2d+IgSDniuXrXpx/jvVbQA0 eHDtIqmGBj7NOk2Szp5lI63Y0jZhF2UMsnLl7TLBOBjHKR5b4nWmwv+SQkR0H83m jTE8Z+w0vUlsckAHTEak5v6jzb4H6aNd4Hhp3zHr3cFcHE+wYegcl6FZGvvQDymU +8cO8wpUR5kN3P8sYUZbrdNmkqbNbFHO3FQ94I2MKn92AeTJrffrAYGe3tn5vnx7 yjFhgApUYwjyNkN3NuJLDL6Zh084EOhX+Po533Xu/74Nom4+CO4b5ZiLsnToKi9P Aw3JCuxlt0xrpGuLP/4C3LWqIYz7THoSrZmPNMea+cN2AZbwLnmOTmL5s7FphKj2 0Q5DfiGrAOyCgTphIB5Ehox+W+Ff+SBGy68onETFeLd2Mx6RY/jvfWEXk+4rbp3J kdehuVSUfkvph3Ny/UjeqNYuYWE+k6S+YVgm/Ag/PMoR2Naf6M0= =1vJ0 -----END PGP SIGNATURE-----
