Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-12302

[ruby-kit] CVE-2024-27282 CVE-2024-27281 CVE-2024-27280 upgrade dev-lang/ruby to 3.0.7, 3.1.5, and 3.2.4

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Fixed
    • Icon: Severe (Ebuild) Severe (Ebuild)
    • None
    • None

      Some new CVEs publicly dropped for upstream Ruby on April 23, 2024:

      1. CVE-2024-27282: Arbitrary memory address read vulnerability with Regex search
      2. CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc
      3. CVE-2024-27280: Buffer overread vulnerability in StringIO

      Our in-tree dev-lang/ruby that are impacted need to be bumped to the new patched versions:

      • 3.0.7
      • 3.1.5
      • 3.2.4

      3.3.1 will be handled in FL-11914

            siris siris
            siris siris
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: