|
|
Log in / Subscribe / Register

Ubuntu alert USN-8556-1 (ruby2.3)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8556-1] Ruby vulnerabilities
Date:  Thu, 16 Jul 2026 15:50:23 +0000
Message-ID:  <E1wkOLv-0004Mp-L8@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8556-1 July 16, 2026 ruby2.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Ruby. Software Description: - ruby2.3: Object-oriented scripting language Details: It was discovered that the Net::IMAP client in Ruby did not properly sanitize Symbol arguments passed to IMAP commands. A remote attacker controlling a malicious IMAP server, or able to influence command arguments, could use this to inject arbitrary IMAP commands via CRLF sequences. (CVE-2026-42258) It was discovered that the Zlib::GzipReader in Ruby did not correctly ensure sufficient buffer capacity in the zstream_buffer_ungets function. An attacker could use this to craft a gzip stream that, when processed, could cause a buffer overflow, resulting in memory corruption and possibly arbitrary code execution. (CVE-2026-27820) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libruby2.3 2.3.1-2~ubuntu16.04.16+esm15 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8556-1 CVE-2026-27820, CVE-2026-42258


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpY/TEACgkQcpJm3tlz hgHi4w/9EJC75nQrs0rvq2PDjmPfW4jhPvIZVYGIVAZwb8m/757svDaoUmFSUk8V wCt64dqgKGKsTO5kBwTaC65pqHwjoolVOo1s5HSmU4h9XvvTJZhSwMq7KayqQEUp KI8NW1Tnz4Vm2OP2zPGZ/p/xa2C7ZPgtScP6q13u+E/JE0RSt9+2SpaKIMu/NED5 SzCKa4qBVFfAFJrF5fOFQELwGzncr65lJl+v5dL6X2d+IgSDniuXrXpx/jvVbQA0 eHDtIqmGBj7NOk2Szp5lI63Y0jZhF2UMsnLl7TLBOBjHKR5b4nWmwv+SQkR0H83m jTE8Z+w0vUlsckAHTEak5v6jzb4H6aNd4Hhp3zHr3cFcHE+wYegcl6FZGvvQDymU +8cO8wpUR5kN3P8sYUZbrdNmkqbNbFHO3FQ94I2MKn92AeTJrffrAYGe3tn5vnx7 yjFhgApUYwjyNkN3NuJLDL6Zh084EOhX+Po533Xu/74Nom4+CO4b5ZiLsnToKi9P Aw3JCuxlt0xrpGuLP/4C3LWqIYz7THoSrZmPNMea+cN2AZbwLnmOTmL5s7FphKj2 0Q5DfiGrAOyCgTphIB5Ehox+W+Ff+SBGy68onETFeLd2Mx6RY/jvfWEXk+4rbp3J kdehuVSUfkvph3Ny/UjeqNYuYWE+k6S+YVgm/Ag/PMoR2Naf6M0= =1vJ0 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds