[ubuntu/resolute-security] ruby3.3 3.3.8-2ubuntu3.1 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Mon Jul 6 09:08:47 UTC 2026
ruby3.3 (3.3.8-2ubuntu3.1) resolute-security; urgency=medium
* SECURITY UPDATE: STARTTLS stripping via pre-injected tagged response
- debian/patches/CVE-2026-42246.patch: add handled flag in starttls(),
guard_against_tagged_response_skipping_handler! in send_command, and
rescue InvalidResponseError to detect and reject pre-injected OK
responses before TLS negotiation begins (net-imap 0.4.19).
- CVE-2026-42246
* SECURITY UPDATE: SCRAM iteration-count denial of service
- debian/patches/CVE-2026-42256.patch: add max_iterations parameter
(default 2**24) to ScramAuthenticator; raise Error in
recv_server_first_message when server-supplied iteration count exceeds
the maximum, preventing unbounded PBKDF2 computation (net-imap 0.4.19).
- CVE-2026-42256
* SECURITY UPDATE: CRLF injection via RawData and setquota command
- debian/patches/CVE-2026-42257.patch: add CRLF/NUL validation in
RawData#validate; rewrite setquota to use typed array encoding
instead of raw string concatenation (net-imap 0.4.19).
- CVE-2026-42257
* debian/patches/skip-test_crypt-s390x.patch: skip TestString#test_crypt
and TestString2#test_crypt on s390x where DES crypt produces different
results due to glibc differences.
Date: 2026-06-25 17:49:11.880055+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/ruby3.3/3.3.8-2ubuntu3.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Resolute-changes
mailing list