{"id":"ALSA-2026:20606","summary":"Important: ruby4.0 security update","details":"Ruby is the interpreted scripting language for quick and easy object-oriented programming. It has many features to process text files and to do system management tasks (as in Perl). It is simple, straight-forward, and extensible.  \n\nSecurity Fix(es):  \n\n  * ruby/json: Ruby JSON: Denial of Service or Information Disclosure via format string injection (CVE-2026-33210)\n  * erb: ERB: Arbitrary code execution via deserialization bypass (CVE-2026-41316)\n\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n","modified":"2026-06-04T11:30:04.377675936Z","published":"2026-05-26T00:00:00Z","related":["CVE-2026-33210","CVE-2026-41316"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:20606"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33210"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-41316"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2449871"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2461369"},{"type":"ADVISORY","url":"https://errata.almalinux.org/10/ALSA-2026-20606.html"}],"affected":[{"package":{"name":"ruby4.0","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/ruby4.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.3-34.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:20606.json"}},{"package":{"name":"ruby4.0-devel","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/ruby4.0-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.3-34.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:20606.json"}},{"package":{"name":"ruby4.0-doc","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/ruby4.0-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.3-34.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:20606.json"}},{"package":{"name":"ruby4.0-rubygem-mysql2","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/ruby4.0-rubygem-mysql2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.7-34.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:20606.json"}},{"package":{"name":"ruby4.0-rubygem-pg","ecosystem":"AlmaLinux:10","purl":"pkg:rpm/almalinux/ruby4.0-rubygem-pg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.3-34.el10_2"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux10/ALSA-2026:20606.json"}}],"schema_version":"1.7.5"}