Mageia 2024-0160: ruby Security Advisory Updates
Summary
Buffer overread vulnerability in StringIO. (CVE-2024-27280)
RCE vulnerability with .rdoc_options in RDoc. (CVE-2024-27281)
Arbitrary memory address read vulnerability with Regex search.
(CVE-2024-27282)
References
- https://bugs.mageia.org/show_bug.cgi?id=33138
- https://www.ruby-lang.org/en/news/2024/04/23/ruby-3-1-5-released/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27280
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27281
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27282
Resolution
MGASA-2024-0160 - Updated ruby packages fix security vulnerabilities
SRPMS
- 9/core/ruby-3.1.5-45.mga9