RHSA-2022:0581HighCVSS 8.8

Red Hat Security Advisory: ruby:2.6 security update

Published
February 21, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2019-15845 — ruby: NUL injection vulnerability of File.fnmatch and File.fnmatch? CVE-2019-16201 — ruby: Regular expression denial of service vulnerability of WEBrick's Digest authentication CVE-2019-16254 — ruby: HTTP response splitting in WEBrick CVE-2019-16255 — ruby: Code injection via command argument of Shell#test / Shell#[] CVE-2020-10663 — rubygem-json: Unsafe object creation vulnerability in JSON CVE-2020-10933 — ruby: BasicSocket#read_nonblock method leads to information disclosure CVE-2020-25613 — ruby: Potential HTTP request smuggling in WEBrick CVE-2020-36327 — rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source CVE-2021-28965 — ruby: XML round-trip vulnerability in REXML CVE-2021-31799 — rubygem-rdoc: Command injection vulnerability in RDoc CVE-2021-31810 — ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host CVE-2021-32066 — ruby: StartTLS stripping vulnerability in Net::IMAP CVE-2021-41817 — ruby: Regular expression denial of service vulnerability of Date parsing methods CVE-2021-41819 — ruby: Cookie prefix spoofing in CGI::Cookie.parse

🎯 Affected products93

  • Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-0:2.6.9-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-0:2.6.9-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-0:2.6.9-107.module+el8.1.0+14088+04cf326e.src (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-0:2.6.9-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-debuginfo-0:2.6.9-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-debuginfo-0:2.6.9-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-debuginfo-0:2.6.9-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-debugsource-0:2.6.9-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-debugsource-0:2.6.9-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-debugsource-0:2.6.9-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-devel-0:2.6.9-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-devel-0:2.6.9-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-devel-0:2.6.9-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-doc-0:2.6.9-107.module+el8.1.0+14088+04cf326e.noarch (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-libs-0:2.6.9-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-libs-0:2.6.9-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-libs-0:2.6.9-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-libs-debuginfo-0:2.6.9-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-libs-debuginfo-0:2.6.9-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • ruby-libs-debuginfo-0:2.6.9-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-abrt-0:0.3.0-4.module+el8.1.0+3653+beb38eb0.noarch (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-abrt-0:0.3.0-4.module+el8.1.0+3653+beb38eb0.src (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-abrt-doc-0:0.3.0-4.module+el8.1.0+3653+beb38eb0.noarch (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-bigdecimal-0:1.4.1-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-bigdecimal-0:1.4.1-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-bigdecimal-0:1.4.1-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-bigdecimal-debuginfo-0:1.4.1-107.module+el8.1.0+14088+04cf326e.i686 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-bigdecimal-debuginfo-0:1.4.1-107.module+el8.1.0+14088+04cf326e.ppc64le (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • rubygem-bigdecimal-debuginfo-0:1.4.1-107.module+el8.1.0+14088+04cf326e.x86_64 (ruby:2.6) as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
  • +63 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: It is possible to test for presence of the NULL byte manually prior to call the affected methods with an untrusted string. Workaround: To mitigate this vulnerability, do not supply untrusted user input and/or untrusted strings to the following method calls or utilize code libraries which do so: ``` JSON(user_input) JSON[user_input, nil] JSON.parse(user_input, nil) JSON::Parser.new(user_input).parse ``` Also note that JSON.load() should never be given input from unknown sources. Workaround: This issue only affects configurations where gem packages are installed from multiple sources and the source repositories are explicitly defined for at least some gems. Dependencies of those source-restricted gems may be installed form a different repository, even if the same repository provides those dependencies, which is inconsistent with the intended behaviour described in the Bundler documentation. There are multiple possible approaches to mitigate this issue - customers should evaluate which approaches are usable in their environments. * Explicitly define source for all dependency gems in the Gemfile configuration. When a dependency of a source-restricted gem is also to be installed form the same source, list such dependency explicitly in the Gemfile along with the specific source. * Avoid configurations with multiple source repositories. When using a private repository for non-public gems, use the same private repository to mirror any content required from any public gem repository, such as RubyGems.org. When preparing such mirror, ensure that no mirrored gems have names conflicting with names of the internal non-public gems. * Reserve internal package names in public repositories. For any internal private gem, also reserve the name in any public gem repository used, such as RubyGems.org. This will prevent attackers from registering those names and providing their malicious gems with higher versions. Additional information about affected configurations can be found in the following Red Hat Knowledgebase article: https://access.redhat.com/articles/6206172

🔗 References (18)