ALASRUBY2.6-2023-001

Related Vulnerabilities: CVE-2022-28739  

A buffer overrun vulnerability was found in Ruby. The issue occurs in a conversion algorithm from a String to a Float that causes process termination due to a segmentation fault, but under limited circumstances. This flaw may cause an illegal memory read. (CVE-2022-28739)

ALASRUBY2.6-2023-001


Amazon Linux 2 Security Advisory: ALASRUBY2.6-2023-001
Advisory Release Date: 2023-08-07 05:23 Pacific
Advisory Updated Date: 2023-09-25 22:02 Pacific
Severity: Medium

Issue Overview:

A buffer overrun vulnerability was found in Ruby. The issue occurs in a conversion algorithm from a String to a Float that causes process termination due to a segmentation fault, but under limited circumstances. This flaw may cause an illegal memory read. (CVE-2022-28739)


Affected Packages:

ruby


Issue Correction:
Run yum update ruby to update your system.

New Packages:
aarch64:
    ruby-2.6.10-129.amzn2.0.1.aarch64
    ruby-devel-2.6.10-129.amzn2.0.1.aarch64
    ruby-libs-2.6.10-129.amzn2.0.1.aarch64
    rubygem-bigdecimal-1.4.1-129.amzn2.0.1.aarch64
    rubygem-io-console-0.4.7-129.amzn2.0.1.aarch64
    rubygem-json-2.1.0-129.amzn2.0.1.aarch64
    rubygem-openssl-2.1.2-129.amzn2.0.1.aarch64
    rubygem-psych-3.1.0-129.amzn2.0.1.aarch64
    ruby-debuginfo-2.6.10-129.amzn2.0.1.aarch64

i686:
    ruby-2.6.10-129.amzn2.0.1.i686
    ruby-devel-2.6.10-129.amzn2.0.1.i686
    ruby-libs-2.6.10-129.amzn2.0.1.i686
    rubygem-bigdecimal-1.4.1-129.amzn2.0.1.i686
    rubygem-io-console-0.4.7-129.amzn2.0.1.i686
    rubygem-json-2.1.0-129.amzn2.0.1.i686
    rubygem-openssl-2.1.2-129.amzn2.0.1.i686
    rubygem-psych-3.1.0-129.amzn2.0.1.i686
    ruby-debuginfo-2.6.10-129.amzn2.0.1.i686

noarch:
    rubygems-3.0.3.1-129.amzn2.0.1.noarch
    rubygems-devel-3.0.3.1-129.amzn2.0.1.noarch
    rubygem-rake-12.3.3-129.amzn2.0.1.noarch
    rubygem-irb-1.0.0-129.amzn2.0.1.noarch
    rubygem-rdoc-6.1.2.1-129.amzn2.0.1.noarch
    ruby-doc-2.6.10-129.amzn2.0.1.noarch
    rubygem-did_you_mean-1.3.0-129.amzn2.0.1.noarch
    rubygem-minitest-5.11.3-129.amzn2.0.1.noarch
    rubygem-power_assert-1.1.3-129.amzn2.0.1.noarch
    rubygem-net-telnet-0.2.0-129.amzn2.0.1.noarch
    rubygem-test-unit-3.2.9-129.amzn2.0.1.noarch
    rubygem-xmlrpc-0.3.0-129.amzn2.0.1.noarch
    rubygem-bundler-1.17.2-129.amzn2.0.1.noarch

src:
    ruby-2.6.10-129.amzn2.0.1.src

x86_64:
    ruby-2.6.10-129.amzn2.0.1.x86_64
    ruby-devel-2.6.10-129.amzn2.0.1.x86_64
    ruby-libs-2.6.10-129.amzn2.0.1.x86_64
    rubygem-bigdecimal-1.4.1-129.amzn2.0.1.x86_64
    rubygem-io-console-0.4.7-129.amzn2.0.1.x86_64
    rubygem-json-2.1.0-129.amzn2.0.1.x86_64
    rubygem-openssl-2.1.2-129.amzn2.0.1.x86_64
    rubygem-psych-3.1.0-129.amzn2.0.1.x86_64
    ruby-debuginfo-2.6.10-129.amzn2.0.1.x86_64