This bug was fixed in the package ruby3.3 - 3.3.8-2.2ubuntu4
---------------
ruby3.3 (3.3.8-2.2ubuntu4) stonking; urgency=medium
* SECURITY UPDATE: STARTTLS stripping via pre-injected tagged response
- debian/patches/CVE-2026-42246.patch: add handled flag in starttls(),
guard_against_tagged_response_skipping_handler! in send_command, and
rescue InvalidResponseError to detect and reject pre-injected OK
responses before TLS negotiation begins (net-imap 0.4.19).
- CVE-2026-42246
* SECURITY UPDATE: SCRAM iteration-count denial of service
- debian/patches/CVE-2026-42256.patch: add max_iterations parameter
(default 2**24) to ScramAuthenticator; raise Error in
recv_server_first_message when server-supplied iteration count exceeds
the maximum, preventing unbounded PBKDF2 computation (net-imap 0.4.19).
- CVE-2026-42256
* SECURITY UPDATE: CRLF injection via RawData and setquota command
- debian/patches/CVE-2026-42257.patch: add CRLF/NUL validation in
RawData#validate; rewrite setquota to use typed array encoding
instead of raw string concatenation (net-imap 0.4.19).
- CVE-2026-42257
-- Leonidas Da Silva Barbosa <[email protected]> Mon, 31 Aug
2026 13:25:36 -0300
** Changed in: ruby3.3 (Ubuntu)
Status: Fix Committed => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-42246
** CVE added: https://cve.org/CVERecord?id=CVE-2026-42256
** CVE added: https://cve.org/CVERecord?id=CVE-2026-42257
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2154838
Title:
ruby3.3: FTBFS with openssl 4.0
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ruby3.3/+bug/2154838/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs