[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2026-82455/rubygems
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 8 19:50:56 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5be5fd4f by Salvatore Bonaccorso at 2026-09-08T20:49:49+02:00
Track fixed version for CVE-2026-82455/rubygems
While the upload for 4.0.20 mentions that it got fixed there, the
upstream change landed already in 4.0.15 back in june. The first version
in unstable containing the fix was 4.0.15-2.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7234,7 +7234,7 @@ CVE-2026-82457 (su-exec through 0.3 fails to validate numeric user and group ide
CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network interface a ...)
NOT-FOR-US: Argo CD
CVE-2026-82455 (RubyGems fails to re-validate path containment after filesystem symlin ...)
- - rubygems <unfixed>
+ - rubygems 4.0.15-2
[trixie] - rubygems <no-dsa> (Minor issue)
[bookworm] - rubygems <postponed> (Minor issue)
NOTE: https://github.com/ruby/rubygems/pull/9493
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5be5fd4f132cb4d87c753ac5996b0c4d834dbcf9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5be5fd4f132cb4d87c753ac5996b0c4d834dbcf9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/0970ab6b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list