Opened 5 months ago

Closed 4 months ago

#23284 closed enhancement (fixed)

ruby-4.0.5

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (8)

comment:1 by Bruce Dubbs, 4 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 4 months ago

Summary: ruby-4.0.4 → ruby-4.0.5

Now version 4.0.5.

comment:3 by Douglas R. Reno, 4 months ago

Priority: normal → high

4.0.5 fixes CVE-2026-46727, rated as 8.1 High

comment:4 by Bruce Dubbs, 4 months ago

Priority: high → elevated

Ruby 4.0.5 has been released.

This release only contains a security fix for CVE-2026-46727: Use-after-free in pthread-based getaddrinfo timeout handler and a build system regression in Ruby 4.0.4 under C locale.

Ruby 4.0.4 has been released.

This is a routine update that includes bugfixes. Please see ​https://github.com/ruby/ruby/releases/tag/v4.0.4 for further details.

Last edited 4 months ago by Bruce Dubbs (previous) (diff)

comment:5 by Bruce Dubbs, 4 months ago

Priority: elevated → high

comment:6 by Bruce Dubbs, 4 months ago

We will need an openssl4 patch for ruby.

ossl_asn1.c:240:9: error: invalid use of incomplete typedef ‘ASN1_BIT_STRING’ {aka ‘struct asn1_string_st’}
  240 |     bstr->flags &= ~(ASN1_STRING_FLAG_BITS_LEFT|0x07); /* clear */
      |         ^~
ossl_asn1.c:240:22: error: ‘ASN1_STRING_FLAG_BITS_LEFT’ undeclared (first use in this function)
  240 |     bstr->flags &= ~(ASN1_STRING_FLAG_BITS_LEFT|0x07); /* clear */
      |                      ^~~~~~~~~~~~~~~~~~~~~~~~~~
ossl_asn1.c:240:22: note: each undeclared identifier is reported only once for each function it appears in
ossl_asn1.c:241:9: error: invalid use of incomplete typedef ‘ASN1_BIT_STRING’ {aka ‘struct asn1_string_st’}

etc

comment:7 by Bruce Dubbs, 4 months ago

Owner: changed from Bruce Dubbs to SecurityAdvisory
Status: assigned → new

Fixed at commit b2119fac7b.

Leaving open for security advisory.

comment:8 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-106 issued

Note: See TracTickets for help on using tickets.