{"id":"openSUSE-SU-2026:21878-1","summary":"Security update for ruby3.4","details":"This update for ruby3.4 fixes the following issues:\n\n- CVE-2025-58767: denial of service when parsing XML containing multiple XML declarations (bsc#1250016).\n- CVE-2026-27820: insufficient checks in `zstream_buffer_ungets` can lead to a buffer overflow (bsc#1259239).\n- CVE-2026-41316: erb: @_init deserialization guard bypass via def_module / def_method / def_class (bsc#1262441).\n- CVE-2026-42258: ruby: Net:IMAP: IMAP Command Injection via Symbol Arguments (bsc#1268011).\n- CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in \"raw\" argument (bsc#1268337).\n- CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338).\n- CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339).\n- CVE-2025-61594: rubygem-uri: URI concatenation with the plus operator can cause credential disclosure (bsc#1255833).\n\nChanges for ruby3.4:\n\n- Update to 3.4.10.\n\n- Update to 3.4.9:\n\n - Bug #21715: Miscompilation on x86-64-v2 due to undefined\n behavior in search_nonascii in string.c - Ruby - Ruby Issue\n Tracking System\n - Bug #21787: IO::Buffer Integer Overflow in Range Validation\n Leads to Out-of-Bounds Memory Access - Ruby - Ruby Issue\n - Bug #21757: Splatted args array is mutated when passing\n unexpected kwargs - Ruby - Ruby Issue Tracking System\n - Bug #21326: Instruction generation differences between parse.y\n and prism for def a(x, ...); b(...); end - Ruby - Ruby Issue\n - Bug #21814: 0.pow(2,-9999999999999999990) should be zero - Ruby\n - Ruby Issue Tracking System\n - Bug #21819: A Data object should be frozen even if it has no\n members - Ruby - Ruby Issue Tracking System\n - Bug #21811: Fix underflow in Array#pack - Ruby - Ruby Issue\n - Bug #21838: Rails seeing degradation (20% slowdown) related to\n Revision 079ef92b \"Implement global allocatable slots and empty\n pages\" (from Sep 5 2024) - Ruby - Ruby Issue Tracking System\n - Bug #21931: GC Crash in String#% (backport\n 726205b354d1068147719fb42e1de743f1838ef1) - Ruby - Ruby Issue\n - Bug #21860: Process.fork: the child may deadlock on\n th-\u003einterrupt_lock in threadptr_interrupt_exec_cleanup - Ruby -\n Ruby Issue Tracking System\n - Bug #21873: UnboundMethod#== returns false for methods from\n included/extended modules - Ruby - Ruby Issue Tracking System\n\n- Update to 3.4.8:\n\n  - Bug #21629: Ruby-3.4.7 prints -Wdefault-const-init-field-unsafe\n warnings on clang / llvm 21 - Ruby - Ruby Issue Tracking System\n - Bug #21626: Backport WASI setjmp handler memory leak fixes -\n Ruby - Ruby Issue Tracking System\n - Bug #21631: Backport openssl gem bugfix releases - Ruby - Ruby\n Issue Tracking System\n - Bug #21632: Backport REXML CVE-2025-58767 fix (bsc#1250016) -\n - Bug #21644: Stack consistency error for the newrange INSN\n peephole optimization with chilled string - Ruby - Ruby Issue\n - Bug #21668: Improve performance of\n UnicodeNormalize.canonical_ordering_one - Ruby - Ruby Issue\n - Bug #21638: Ractor-local $DEBUG is not marked - Ruby - Ruby\n - Bug #21652: Marshal#dump documentation out-of-date/unclear\n regarding Data class - Ruby - Ruby Issue Tracking System\n - Bug #13671: Regexp with lookbehind and case-insensitivity\n raises RegexpError only on strings with certain characters -\n - Bug #21625: Allow IO#wait_readable together with IO#ungetc even\n in text mode - Ruby - Ruby Issue Tracking System\n - Bug #21671: Rails CI raises Assertion Failed:\n rbimpl_rstring_getmem:RB_TYPE_P(str, RUBY_T_STRING): actual\n type: 26 with \"-DENABLE_PATH_CHECK=0 -DRUBY_DEBUG=1\" enabled -\n - Update next stable version to 4.0 from 3.5 by hsbt . Pull\n Request #15146\n - Bug #21679: Segfault when ruby calls pthread_detach in\n rb_getnameinfo - Ruby - Ruby Issue Tracking System\n - Bug #21694: Crash when looking up super method from BasicObject\n - Ruby - Ruby Issue Tracking System\n - Bug #21707: Destructuring assignment of SimpleDelegator wrapped\n array bug with YJIT - Ruby - Ruby Issue Tracking System\n - Bug #21265: Crash when proc from Symbol#to_proc called outside\n refinement scope - Ruby - Ruby Issue Tracking System\n - Bug #21703: RUBY_CRASH_REPORT does not work when shelling out\n in some cases - Ruby - Ruby Issue Tracking System\n - Bug #21666: Math.lgamma(-1).should == [infinity_value, 1] fails\n with Fedora glibc-2.42.9000-8.fc44 - Ruby - Ruby Issue Tracking\n System\n - Bug #21655: segfault when building 3.3.10 with GCC 15.2.1,\n regression from 3.3.9 - Ruby - Ruby Issue Tracking System\n - Bug #21680: Integer#digits bug starting from Ruby 3.1 - Ruby -\n - Bug #21705: UNIXServer.open(nil) segfaults on Windows - Ruby -\n - Bug #21648: [prism] ruby crashes for for * in [10]; end - Ruby\n - Bug #21187: Strings concatenated with \\ getting frozen with\n literal hashes (PRISM only) - Ruby - Ruby Issue Tracking System\n - Bug #21772: ruby: YJIT has panicked StackOpnd(1) should be a\n heap object, but was ImmSymbol for VALUE(137647867319760) -\n - Bug #21446: StackOverflow when changing visibility in reopened\n refinement - Ruby - Ruby Issue Tracking System\n - Bug #21779: Do not export functions from statically linked\n extensions - Ruby - Ruby Issue Tracking System\n - Bug #21266: YJIT GC safety crash with proc objects as block\n argument - Ruby - Ruby Issue Tracking System\n","modified":"2026-09-25T18:23:10.633194964Z","published":"2026-09-18T13:34:12Z","related":["CVE-2025-58767","CVE-2025-61594","CVE-2026-27820","CVE-2026-41316","CVE-2026-42258","CVE-2026-47240","CVE-2026-47241","CVE-2026-47242"],"upstream":["CVE-2025-58767","CVE-2025-61594","CVE-2026-27820","CVE-2026-41316","CVE-2026-42258","CVE-2026-47240","CVE-2026-47241","CVE-2026-47242"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250016"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255833"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259239"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262441"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268337"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268338"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268339"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58767"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-61594"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27820"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42258"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47240"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47241"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47242"}],"affected":[{"package":{"name":"ruby3.4","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ruby3.4&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.10-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"ruby3.4-doc":"3.4.10-160000.1.1","ruby3.4-doc-ri":"3.4.10-160000.1.1","libruby3_4-3_4":"3.4.10-160000.1.1","ruby3.4":"3.4.10-160000.1.1","ruby3.4-devel":"3.4.10-160000.1.1","ruby3.4-devel-extra":"3.4.10-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21878-1.json"}}],"schema_version":"1.9.0"}