Opened 5 months ago

Closed 5 months ago

#23181 closed enhancement (fixed)

ruby-4.0.3

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Joe Locash, 5 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 5 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Priority: normal → elevated
Status: assigned → new
4.0.3

What's Changed
  - Prohibit def_method on marshal-loaded ERB instances (CVE-2026-41316)

Full Changelog: ​v4.0.2...v4.0.3

Fixed at 53a7f876c7. Leaving open for SA.

comment:3 by Douglas R. Reno, 5 months ago

Priority: elevated → high

The issue appears to be rated as 8.1 High, see ​https://nvd.nist.gov/vuln/detail/CVE-2026-41316 - promoting to High as a result.

comment:4 by Douglas R. Reno, 5 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-061 issued

Note: See TracTickets for help on using tickets.