[ubuntu/jammy-security] ruby3.0 3.0.2-7ubuntu2.13 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Sat Jul 4 15:42:53 UTC 2026


ruby3.0 (3.0.2-7ubuntu2.13) jammy-security; urgency=medium

  * SECURITY UPDATE: STARTTLS stripping via pre-injected tagged response
    - debian/patches/CVE-2026-42246.patch: add handled flag in starttls(),
      guard_against_tagged_response_skipping_handler! in send_command, and
      InvalidResponseError class to detect and reject pre-injected OK
      responses before TLS negotiation begins.
    - CVE-2026-42246
  * SECURITY UPDATE: CRLF injection via RawData and setquota command
    - debian/patches/CVE-2026-42257.patch: add CRLF/NUL validation in
      RawData#validate; rewrite setquota to use typed array encoding
      instead of raw string concatenation.
    - CVE-2026-42257

Date: 2026-06-17 18:12:11.457536+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.13
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list