Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5be5fd4f by Salvatore Bonaccorso at 2026-09-08T20:49:49+02:00
Track fixed version for CVE-2026-82455/rubygems
While the upload for 4.0.20 mentions that it got fixed there, the
upstream change landed already in 4.0.15 back in june. The first version
in unstable containing the fix was 4.0.15-2.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7234,7 +7234,7 @@ CVE-2026-82457 (su-exec through 0.3 fails to validate
numeric user and group ide
CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network
interface a ...)
NOT-FOR-US: Argo CD
CVE-2026-82455 (RubyGems fails to re-validate path containment after
filesystem symlin ...)
- - rubygems <unfixed>
+ - rubygems 4.0.15-2
[trixie] - rubygems <no-dsa> (Minor issue)
[bookworm] - rubygems <postponed> (Minor issue)
NOTE: https://github.com/ruby/rubygems/pull/9493
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5be5fd4f132cb4d87c753ac5996b0c4d834dbcf9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5be5fd4f132cb4d87c753ac5996b0c4d834dbcf9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits