[El-errata] ELSA-2026-33540 Important: Oracle Linux 10 ruby4.0 security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Fri Jul 17 16:57:35 UTC 2026
Oracle Linux Security Advisory ELSA-2026-33540
http://linux.oracle.com/errata/ELSA-2026-33540.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
ruby4.0-4.0.3-35.el10_2.x86_64.rpm
ruby4.0-devel-4.0.3-35.el10_2.x86_64.rpm
ruby4.0-doc-4.0.3-35.el10_2.noarch.rpm
ruby4.0-rubygem-mysql2-0.5.7-35.el10_2.x86_64.rpm
ruby4.0-rubygem-pg-1.6.3-35.el10_2.x86_64.rpm
aarch64:
ruby4.0-4.0.3-35.el10_2.aarch64.rpm
ruby4.0-devel-4.0.3-35.el10_2.aarch64.rpm
ruby4.0-doc-4.0.3-35.el10_2.noarch.rpm
ruby4.0-rubygem-mysql2-0.5.7-35.el10_2.aarch64.rpm
ruby4.0-rubygem-pg-1.6.3-35.el10_2.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/ruby4.0-4.0.3-35.el10_2.src.rpm
Related CVEs:
CVE-2026-42245
CVE-2026-42246
CVE-2026-42258
Description of changes:
[4.0.3-35]
- Fix Net::IMAP ResponseReader quadratic complexity vulnerability (CVE-2026-42245)
Includes core fix plus additional performance optimizations
Resolves: RHEL-181675
- Fix Net::IMAP STARTTLS stripping vulnerability (CVE-2026-42246)
Resolves: RHEL-181767
- Fix Net::IMAP command injection vulnerability via unvalidated Symbol arguments (CVE-2026-42258)
Resolves: RHEL-181793
[4.0.3-34]
- Upgrade to Ruby 4.0.3.
Resolves: RHEL-171239
- Fix ERB: Arbitrary code execution via bypass
(CVE-2026-41316)
Resolves: RHEL-170910
- Fix JSON: Denial of Service or Information Disclosure via format string injection
(CVE-2026-33210)
Resolves: RHEL-173457
More information about the El-errata
mailing list