7.5
CVSSv3

CVE-2022-28739

Published: 09/05/2022 Updated: 24/01/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

There is a buffer over-read in Ruby prior to 2.6.10, 2.7.x prior to 2.7.6, 3.x prior to 3.0.4, and 3.1.x prior to 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ruby-lang ruby

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

apple macos

Vendor Advisories

Debian Bug report logs - #1009956 ruby30: CVE-2022-28739 Package: src:ruby30; Maintainer for src:ruby30 is Debian Ruby Team <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Apr 2022 08:54:01 UTC Severity: important Tags: security, upstream ...
Several security issues were fixed in Ruby ...
Ruby could be made to crash or read sensitive information when processing certain input ...
Synopsis Moderate: ruby:27 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the ruby:27 module is now available for Red Hat Enterprise Linux 8Red Hat Product Securi ...
Synopsis Moderate: ruby:30 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the ruby:30 module is now available for Red Hat Enterprise Linux 8Red Hat Product Securi ...
Synopsis Moderate: ruby:26 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the ruby:26 module is now available for Red Hat Enterprise Linux 8Red Hat Product Securi ...
Synopsis Moderate: ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for ruby is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this u ...
Synopsis Moderate: rh-ruby27-ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-ruby27-ruby is now available for Red Hat Software CollectionsRed Hat Product Sec ...
Synopsis Moderate: rh-ruby30-ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-ruby30-ruby is now available for Red Hat Software CollectionsRed Hat Product Sec ...
概要 Moderate: ruby:25 security update タイプ/重大度 Security Advisory: Moderate Red Hat Insights パッチ分析 このアドバイザリーの影響を受けるシステムを特定し、修正します。 影響を受けるシステムの表示 トピック An update for the ruby:25 module is now available for Red Hat E ...
A buffer overrun vulnerability was found in Ruby The issue occurs in a conversion algorithm from a String to a Float that causes process termination due to a segmentation fault, but under limited circumstances This flaw may cause an illegal memory read (CVE-2022-28739) ...
A double-free vulnerability was found in Ruby The issue occurs during Regexp compilation This flaw allows an attacker to create a Regexp object with a crafted source string that could cause the same memory to be freed twice (CVE-2022-28738) A buffer overrun vulnerability was found in Ruby The issue occurs in a conversion algorithm from a String ...
A buffer overrun vulnerability was found in Ruby The issue occurs in a conversion algorithm from a String to a Float that causes process termination due to a segmentation fault, but under limited circumstances This flaw may cause an illegal memory read (CVE-2022-28739) ...
A buffer overrun vulnerability was found in Ruby The issue occurs in a conversion algorithm from a String to a Float that causes process termination due to a segmentation fault, but under limited circumstances This flaw may cause an illegal memory read (CVE-2022-28739) ...
out-of-bounds read in string-to-float conversion ...