|
|
Log in / Subscribe / Register

Debian alert DLA-4716-1 (ruby2.7)

From:  Abhijith PA <abhijith@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4716-1] ruby2.7 security update
Date:  Tue, 04 Aug 2026 10:51:09 +0530
Message-ID:  <anF2xfmdCVL_uRMK@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4716-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Abhijith PA August 04, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ruby2.7 Version : 2.7.4-1+deb11u6 $bookworm_VERSION CVE ID : CVE-2025-24294 CVE-2025-61594 CVE-2026-27820 CVE-2026-41316 Ruby a popular language was affected by multiple vulnerabilities CVE-2025-24294 The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. CVE-2025-61594 Using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. URI is a module providing classes to handle Uniform Resource Identifiers. CVE-2026-27820 A buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. CVE-2026-41316 A deserialization vulnerability exists in ERB. Any Ruby application that calls Marshal.load on untrusted data AND has both erb and activesupport loaded is vulnerable to arbitrary code execution. For Debian 11 bullseye, these problems have been fixed in version 2.7.4-1+deb11u6. We recommend that you upgrade your ruby2.7 packages. For the detailed security status of ruby2.7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby2.7 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmpxdsUACgkQhj1N8u2c KO9dJg/9Fwvc8AjyReoQwSu7Ichy2OOQs6+DZUTeBl3SomemPX3D5vkAyFxdDse4 Ix9VRno2hRm/GqNRlChQvHQK9+QHmWhA9Djk66gRYRGoOsUJkMEuhaay2I4YuaTI NqfPXGOxXbs1Woa8SEX5qFrbGpPxkUrjJ5tUeaXlY/mtZwrayQPvD1EyrR/PdFFY XnNVseemzUSFWgiArwsyNrBZZcWVfiupGw6oX2o7hZYgvqzqykq6qDWy94Ph78PL 1z6pTkpgeiDi4q7POSyIg2QTLRudhulmQGAdu9CZJOdvGTzXQf5TU5KgkuTTohzL ovniTdy4OCl//C6Xpt6DHphM4xTPtyJcIebsOVNCyPVJcnn2dmCxYwgwYwRe67Np SeZqtQUrz/CAuInII+zBZlluqNegVOVMLYEhc6lrsg30knqXeylvZm/Ir8QfNq4q FC35G5zSE7rWKD0GGBhkyQkVQ88iiOTV3qX7GRsK3aa2KvHqi/JRkWxqQVcqBEP4 I0ESoYkJDIYYRBjDZWxzlh65eB5lrWJEaqNU/pvmGGqwk/MP8+edKvaeFddSiBDG pgCy54h3i39HDwkkM0gWI7Bj4hMQeX0FWNUWXpiHCU+tzLKm50pIgsWJg3JURblU DbHgfjxh4fcqfXNfX7W5SAyDI6KZISxIu6+vmANduxSReIfaYxk= =T/QH -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds