-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4716-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
August 04, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : ruby2.7
Version : 2.7.4-1+deb11u6 $bookworm_VERSION
CVE ID : CVE-2025-24294 CVE-2025-61594 CVE-2026-27820
CVE-2026-41316
Ruby a popular language was affected by multiple vulnerabilities
CVE-2025-24294
The vulnerability is caused by an insufficient check on the length
of a decompressed domain name within a DNS packet. An attacker can
craft a malicious DNS packet containing a highly compressed domain
name. When the resolv library parses such a packet, the name
decompression process consumes a large amount of CPU resources, as
the library does not limit the resulting length of the name. This
resource consumption can cause the application thread to become
unresponsive, resulting in a Denial of Service condition.
CVE-2025-61594
Using the + operator to combine URIs, sensitive information like
passwords from the original URI can be leaked, violating RFC3986
and making applications vulnerable to credential exposure. URI is
a module providing classes to handle Uniform Resource
Identifiers.
CVE-2026-27820
A buffer overflow vulnerability in the Zlib::GzipReader. The
zstream_buffer_ungets function prepends caller-provided bytes
ahead of previously produced output but fails to guarantee the
backing Ruby string has enough capacity before the memmove shifts
the existing data. This can lead to memory corruption when the
buffer length exceeds capacity.
CVE-2026-41316
A deserialization vulnerability exists in ERB. Any Ruby
application that calls Marshal.load on untrusted data AND has both
erb and activesupport loaded is vulnerable to arbitrary code
execution.
For Debian 11 bullseye, these problems have been fixed in version
2.7.4-1+deb11u6.
We recommend that you upgrade your ruby2.7 packages.
For the detailed security status of ruby2.7 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ruby2.7
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmpxdsUACgkQhj1N8u2c
KO9dJg/9Fwvc8AjyReoQwSu7Ichy2OOQs6+DZUTeBl3SomemPX3D5vkAyFxdDse4
Ix9VRno2hRm/GqNRlChQvHQK9+QHmWhA9Djk66gRYRGoOsUJkMEuhaay2I4YuaTI
NqfPXGOxXbs1Woa8SEX5qFrbGpPxkUrjJ5tUeaXlY/mtZwrayQPvD1EyrR/PdFFY
XnNVseemzUSFWgiArwsyNrBZZcWVfiupGw6oX2o7hZYgvqzqykq6qDWy94Ph78PL
1z6pTkpgeiDi4q7POSyIg2QTLRudhulmQGAdu9CZJOdvGTzXQf5TU5KgkuTTohzL
ovniTdy4OCl//C6Xpt6DHphM4xTPtyJcIebsOVNCyPVJcnn2dmCxYwgwYwRe67Np
SeZqtQUrz/CAuInII+zBZlluqNegVOVMLYEhc6lrsg30knqXeylvZm/Ir8QfNq4q
FC35G5zSE7rWKD0GGBhkyQkVQ88iiOTV3qX7GRsK3aa2KvHqi/JRkWxqQVcqBEP4
I0ESoYkJDIYYRBjDZWxzlh65eB5lrWJEaqNU/pvmGGqwk/MP8+edKvaeFddSiBDG
pgCy54h3i39HDwkkM0gWI7Bj4hMQeX0FWNUWXpiHCU+tzLKm50pIgsWJg3JURblU
DbHgfjxh4fcqfXNfX7W5SAyDI6KZISxIu6+vmANduxSReIfaYxk=
=T/QH
-----END PGP SIGNATURE-----