[Git][security-tracker-team/security-tracker][master] Track fixed version for CVE-2026-82455/rubygems

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 8 19:50:56 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5be5fd4f by Salvatore Bonaccorso at 2026-09-08T20:49:49+02:00
Track fixed version for CVE-2026-82455/rubygems

While the upload for 4.0.20 mentions that it got fixed there, the
upstream change landed already in 4.0.15 back in june. The first version
in unstable containing the fix was 4.0.15-2.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7234,7 +7234,7 @@ CVE-2026-82457 (su-exec through 0.3 fails to validate numeric user and group ide
 CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network interface a ...)
 	NOT-FOR-US: Argo CD
 CVE-2026-82455 (RubyGems fails to re-validate path containment after filesystem symlin ...)
-	- rubygems <unfixed>
+	- rubygems 4.0.15-2
 	[trixie] - rubygems <no-dsa> (Minor issue)
 	[bookworm] - rubygems <postponed> (Minor issue)
 	NOTE: https://github.com/ruby/rubygems/pull/9493



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5be5fd4f132cb4d87c753ac5996b0c4d834dbcf9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5be5fd4f132cb4d87c753ac5996b0c4d834dbcf9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/0970ab6b/attachment.htm>


More information about the debian-security-tracker-commits mailing list