This bug was fixed in the package ruby3.3 - 3.3.8-2.2ubuntu4

---------------
ruby3.3 (3.3.8-2.2ubuntu4) stonking; urgency=medium

  * SECURITY UPDATE: STARTTLS stripping via pre-injected tagged response
    - debian/patches/CVE-2026-42246.patch: add handled flag in starttls(),
      guard_against_tagged_response_skipping_handler! in send_command, and
      rescue InvalidResponseError to detect and reject pre-injected OK
      responses before TLS negotiation begins (net-imap 0.4.19).
    - CVE-2026-42246
  * SECURITY UPDATE: SCRAM iteration-count denial of service
    - debian/patches/CVE-2026-42256.patch: add max_iterations parameter
      (default 2**24) to ScramAuthenticator; raise Error in
      recv_server_first_message when server-supplied iteration count exceeds
      the maximum, preventing unbounded PBKDF2 computation (net-imap 0.4.19).
    - CVE-2026-42256
  * SECURITY UPDATE: CRLF injection via RawData and setquota command
    - debian/patches/CVE-2026-42257.patch: add CRLF/NUL validation in
      RawData#validate; rewrite setquota to use typed array encoding
      instead of raw string concatenation (net-imap 0.4.19).
    - CVE-2026-42257

 -- Leonidas Da Silva Barbosa <[email protected]>  Mon, 31 Aug
2026 13:25:36 -0300

** Changed in: ruby3.3 (Ubuntu)
       Status: Fix Committed => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-42246

** CVE added: https://cve.org/CVERecord?id=CVE-2026-42256

** CVE added: https://cve.org/CVERecord?id=CVE-2026-42257

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153250

Title:
  Merge ruby3.3 from Debian for stonking cycle

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ruby3.3/+bug/2153250/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to