Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (36)
📋 Description
CVE-2008-1891 — ruby: WEBrick CGI source disclosure CVE-2008-2662 — ruby: Integer overflows in rb_str_buf_append() CVE-2008-2663 — ruby: Integer overflows in rb_ary_store() CVE-2008-2664 — ruby: Unsafe use of alloca in rb_str_format() CVE-2008-2725 — ruby: integer overflow in rb_ary_splice/update/replace() - REALLOC_N CVE-2008-2726 — ruby: integer overflow in rb_ary_splice/update/replace() - beg + rlen CVE-2008-3655 — ruby: multiple insufficient safe mode restrictions CVE-2008-3656 — ruby: WEBrick DoS vulnerability (CPU consumption) CVE-2008-3657 — ruby: missing "taintness" checks in dl module CVE-2008-3905 — ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module CVE-2009-5147 — ruby: dlopen could open a library with tainted library name CVE-2011-0188 — ruby: memory corruption in BigDecimal on 64bit platforms CVE-2011-2686 — ruby: Properly initialize the random number generator when forking new process CVE-2011-2705 — ruby: Properly initialize the random number generator when forking new process CVE-2011-3009 — ruby: Properly initialize the random number generator when forking new process CVE-2011-4815 — ruby: hash table collisions CPU usage DoS (oCERT-2011-003) CVE-2012-5371 — ruby: Murmur hash-flooding DoS flaw in ruby 1.9 (oCERT-2012-001) CVE-2013-1821 — ruby: entity expansion DoS vulnerability in REXML CVE-2014-4975 — ruby: off-by-one stack-based buffer overflow in the encodes() function CVE-2014-6438 — ruby: Unsafe parsing of long strings via decode_www_form_component method CVE-2014-8080 — ruby: REXML billion laughs attack via parameter entity expansion CVE-2014-8090 — ruby: REXML incomplete fix for CVE-2014-8080 CVE-2015-7551 — ruby: dlopen could open a library with tainted library name CVE-2015-9096 — ruby: SMTP command injection via CRLF sequences in RCPT TO or MAIL FROM commands in Net::SMTP CVE-2017-10784 — ruby: Escape sequence injection vulnerability in the Basic authentication of WEBrick CVE-2017-14064 — ruby: Arbitrary heap exposure during a JSON.generate call CVE-2018-8780 — ruby: Unintentional directory traversal by poisoned NULL byte in Dir CVE-2019-16254 — ruby: HTTP response splitting in WEBrick CVE-2020-25613 — ruby: Potential HTTP request smuggling in WEBrick CVE-2021-28965 — ruby: XML round-trip vulnerability in REXML CVE-2021-31810 — ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host CVE-2021-41819 — ruby: Cookie prefix spoofing in CGI::Cookie.parse CVE-2022-28739 — ruby: Buffer overrun in String-to-Float conversion CVE-2023-28756 — ruby: ReDoS vulnerability in Time CVE-2024-27282 — ruby: Arbitrary memory address read vulnerability with Regex search CVE-2026-27820 — zlib: zlib: Memory corruption via buffer overflow in Zlib::GzipReader
🎯 Affected products5
- Red Hat Hardened Images
- ruby4-0-main@aarch64 as a component of Red Hat Hardened Images
- ruby4-0-main@noarch as a component of Red Hat Hardened Images
- ruby4-0-main@src as a component of Red Hat Hardened Images
- ruby4-0-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: It is possible to test for presence of the NULL byte manually prior to call a Dir method with an untrusted string. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (40)
- selfhttps://access.redhat.com/errata/RHSA-2026:8838
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-27820
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2008-3905
- externalhttps://access.redhat.com/security/cve/CVE-2008-3657
- externalhttps://access.redhat.com/security/cve/CVE-2008-3656
- externalhttps://access.redhat.com/security/cve/CVE-2008-3655
- externalhttps://access.redhat.com/security/cve/CVE-2024-27282
- externalhttps://access.redhat.com/security/cve/CVE-2021-31810
- externalhttps://access.redhat.com/security/cve/CVE-2019-16254
- externalhttps://access.redhat.com/security/cve/CVE-2018-8780
- externalhttps://access.redhat.com/security/cve/CVE-2017-14064
- externalhttps://access.redhat.com/security/cve/CVE-2017-10784
- externalhttps://access.redhat.com/security/cve/CVE-2015-9096
- externalhttps://access.redhat.com/security/cve/CVE-2014-8090
- externalhttps://access.redhat.com/security/cve/CVE-2014-8080
- externalhttps://access.redhat.com/security/cve/CVE-2014-6438
- externalhttps://access.redhat.com/security/cve/CVE-2014-4975
- externalhttps://access.redhat.com/security/cve/CVE-2013-1821
- externalhttps://access.redhat.com/security/cve/CVE-2012-5371
- externalhttps://access.redhat.com/security/cve/CVE-2011-4815
- externalhttps://access.redhat.com/security/cve/CVE-2008-1891
- externalhttps://access.redhat.com/security/cve/CVE-2023-28756
- externalhttps://access.redhat.com/security/cve/CVE-2022-28739
- externalhttps://access.redhat.com/security/cve/CVE-2021-41819
- externalhttps://access.redhat.com/security/cve/CVE-2021-28965
- externalhttps://access.redhat.com/security/cve/CVE-2020-25613
- externalhttps://access.redhat.com/security/cve/CVE-2011-0188
- externalhttps://access.redhat.com/security/cve/CVE-2008-2662
- externalhttps://access.redhat.com/security/cve/CVE-2008-2725
- externalhttps://access.redhat.com/security/cve/CVE-2008-2726
- externalhttps://access.redhat.com/security/cve/CVE-2008-2663
- externalhttps://access.redhat.com/security/cve/CVE-2008-2664
- externalhttps://access.redhat.com/security/cve/CVE-2011-3009
- externalhttps://access.redhat.com/security/cve/CVE-2011-2686
- externalhttps://access.redhat.com/security/cve/CVE-2011-2705
- externalhttps://access.redhat.com/security/cve/CVE-2009-5147
- externalhttps://access.redhat.com/security/cve/CVE-2015-7551
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8838.json