-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4716-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
August 04, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : ruby2.7
Version        : 2.7.4-1+deb11u6 $bookworm_VERSION
CVE ID         : CVE-2025-24294 CVE-2025-61594 CVE-2026-27820
                 CVE-2026-41316


Ruby a popular language was affected by multiple vulnerabilities
 
CVE-2025-24294

    The vulnerability is caused by an insufficient check on the length
    of a decompressed domain name within a DNS packet. An attacker can
    craft a malicious DNS packet containing a highly compressed domain
    name. When the resolv library parses such a packet, the name
    decompression process consumes a large amount of CPU resources, as
    the library does not limit the resulting length of the name. This
    resource consumption can cause the application thread to become
    unresponsive, resulting in a Denial of Service condition.

CVE-2025-61594

     Using the + operator to combine URIs, sensitive information like
     passwords from the original URI can be leaked, violating RFC3986
     and making applications vulnerable to credential exposure. URI is
     a module providing classes to handle Uniform Resource
     Identifiers.

CVE-2026-27820

    A buffer overflow vulnerability in the Zlib::GzipReader. The
    zstream_buffer_ungets function prepends caller-provided bytes
    ahead of previously produced output but fails to guarantee the
    backing Ruby string has enough capacity before the memmove shifts
    the existing data. This can lead to memory corruption when the
    buffer length exceeds capacity.

CVE-2026-41316

    A deserialization vulnerability exists in ERB. Any Ruby
    application that calls Marshal.load on untrusted data AND has both
    erb and activesupport loaded is vulnerable to arbitrary code
    execution.

For Debian 11 bullseye, these problems have been fixed in version
2.7.4-1+deb11u6.

We recommend that you upgrade your ruby2.7 packages.

For the detailed security status of ruby2.7 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ruby2.7

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmpxdsUACgkQhj1N8u2c
KO9dJg/9Fwvc8AjyReoQwSu7Ichy2OOQs6+DZUTeBl3SomemPX3D5vkAyFxdDse4
Ix9VRno2hRm/GqNRlChQvHQK9+QHmWhA9Djk66gRYRGoOsUJkMEuhaay2I4YuaTI
NqfPXGOxXbs1Woa8SEX5qFrbGpPxkUrjJ5tUeaXlY/mtZwrayQPvD1EyrR/PdFFY
XnNVseemzUSFWgiArwsyNrBZZcWVfiupGw6oX2o7hZYgvqzqykq6qDWy94Ph78PL
1z6pTkpgeiDi4q7POSyIg2QTLRudhulmQGAdu9CZJOdvGTzXQf5TU5KgkuTTohzL
ovniTdy4OCl//C6Xpt6DHphM4xTPtyJcIebsOVNCyPVJcnn2dmCxYwgwYwRe67Np
SeZqtQUrz/CAuInII+zBZlluqNegVOVMLYEhc6lrsg30knqXeylvZm/Ir8QfNq4q
FC35G5zSE7rWKD0GGBhkyQkVQ88iiOTV3qX7GRsK3aa2KvHqi/JRkWxqQVcqBEP4
I0ESoYkJDIYYRBjDZWxzlh65eB5lrWJEaqNU/pvmGGqwk/MP8+edKvaeFddSiBDG
pgCy54h3i39HDwkkM0gWI7Bj4hMQeX0FWNUWXpiHCU+tzLKm50pIgsWJg3JURblU
DbHgfjxh4fcqfXNfX7W5SAyDI6KZISxIu6+vmANduxSReIfaYxk=
=T/QH
-----END PGP SIGNATURE-----

Reply via email to