CVE-2022-28738

medium
Published 2022-09-20 Β· Modified 2022-10-19
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: ruby security, bug fix, and enhancement update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description Ruby: Double free in Regexp compilation Red Hat statement Ruby 2.6 series and 2.7 series are not affected. CVSS v3: 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8ruby:3.0-8060020220810162001.ad008a3aRHSA-2022:64502022-09-13T00:00:00Z Red Hat Enterprise Linux…

Description

Ruby: Double free in Regexp compilation

Red Hat statement

Ruby 2.6 series and 2.7 series are not affected.

CVSS v3: 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8ruby:3.0-8060020220810162001.ad008a3aRHSA-2022:64502022-09-13T00:00:00Z
Red Hat Enterprise Linux 9ruby-0:3.0.4-160.el9_0RHSA-2022:65852022-09-20T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-ruby30-ruby-0:3.0.4-149.el7RHSA-2022:68552022-10-11T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6rubyNot affected
Red Hat Enterprise Linux 7rubyNot affected
Red Hat Enterprise Linux 8ruby:2.5/rubyNot affected
Red Hat Enterprise Linux 8ruby:2.6/rubyNot affected
Red Hat Enterprise Linux 8ruby:2.7/rubyNot affected
Red Hat Software Collectionsrh-ruby27-rubyNot affected

Apply commands

bash fix
Apply RHSA-2022:6450 for Red Hat Enterprise Linux 8
yum update -y ruby:3
# or:
dnf upgrade -y ruby:3

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Software CollectionsNot affected

OS impact

almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed rubygem-typeprof-0.15.2-160.el9_0.noarch.rpm
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 3.0.4-1
debian Debian Fixed 1 release
VersionStatusFixed in
bullseye Fixed 0
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.