Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Mageia 8 MGASA-2022-0143 Moderate: Ruby Double Free And Overrun

mageia
Calendar Grey April 15, 2022
Dist Mageia Esm H88
Recent ruby updates for Mageia resolve issues related to double free and buffer overrun vulnerabilities. Refer to advisory MGASA-2022-0143 for detailed information.
Double free in Regexp compilation (CVE-2022-28738)

Summary

Double free in Regexp compilation (CVE-2022-28738). A buffer overrun was found in String-to-Float conversion (CVE-2022-28739).

References

- https://bugs.mageia.org/show_bug.cgi?id=30278

- https://www.ruby-lang.org/en/news/2022/04/12/buffer-overrun-in-string-to-float-cve-2022-28739/

- https://www.cve.org/CVERecord?id=CVE-2022-28738

- https://www.cve.org/CVERecord?id=CVE-2022-28739

Resolution

SRPMS

- 8/core/ruby-2.7.6-33.4.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 15 Apr 2022
URL: https://advisories.mageia.org/MGASA-2022-0143.html
Type: security
CVE: CVE-2022-28738, CVE-2022-28739

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here