[ubuntu/jammy-security] ruby3.0 3.0.2-7ubuntu2.13 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Sat Jul 4 15:42:53 UTC 2026
ruby3.0 (3.0.2-7ubuntu2.13) jammy-security; urgency=medium
* SECURITY UPDATE: STARTTLS stripping via pre-injected tagged response
- debian/patches/CVE-2026-42246.patch: add handled flag in starttls(),
guard_against_tagged_response_skipping_handler! in send_command, and
InvalidResponseError class to detect and reject pre-injected OK
responses before TLS negotiation begins.
- CVE-2026-42246
* SECURITY UPDATE: CRLF injection via RawData and setquota command
- debian/patches/CVE-2026-42257.patch: add CRLF/NUL validation in
RawData#validate; rewrite setquota to use typed array encoding
instead of raw string concatenation.
- CVE-2026-42257
Date: 2026-06-17 18:12:11.457536+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.13
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list