[ubuntu/resolute-security] ruby3.3 3.3.8-2ubuntu3.1 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Mon Jul 6 09:08:47 UTC 2026


ruby3.3 (3.3.8-2ubuntu3.1) resolute-security; urgency=medium

  * SECURITY UPDATE: STARTTLS stripping via pre-injected tagged response
    - debian/patches/CVE-2026-42246.patch: add handled flag in starttls(),
      guard_against_tagged_response_skipping_handler! in send_command, and
      rescue InvalidResponseError to detect and reject pre-injected OK
      responses before TLS negotiation begins (net-imap 0.4.19).
    - CVE-2026-42246
  * SECURITY UPDATE: SCRAM iteration-count denial of service
    - debian/patches/CVE-2026-42256.patch: add max_iterations parameter
      (default 2**24) to ScramAuthenticator; raise Error in
      recv_server_first_message when server-supplied iteration count exceeds
      the maximum, preventing unbounded PBKDF2 computation (net-imap 0.4.19).
    - CVE-2026-42256
  * SECURITY UPDATE: CRLF injection via RawData and setquota command
    - debian/patches/CVE-2026-42257.patch: add CRLF/NUL validation in
      RawData#validate; rewrite setquota to use typed array encoding
      instead of raw string concatenation (net-imap 0.4.19).
    - CVE-2026-42257
  * debian/patches/skip-test_crypt-s390x.patch: skip TestString#test_crypt
    and TestString2#test_crypt on s390x where DES crypt produces different
    results due to glibc differences.

Date: 2026-06-25 17:49:11.880055+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/ruby3.3/3.3.8-2ubuntu3.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list