RHSA-2026:37397: Important: ruby security update
Important: ruby security update
Other sources
Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.Security Fix(es): ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258) net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/ruby-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.0.648-39.el7_9.1 - Upgrade
Upgrade
redhat/ruby-develto a version that resolves this vulnerability.Fixed in 2.0.0.648-39.el7_9.1 - Upgrade
Upgrade
redhat/ruby-docto a version that resolves this vulnerability.Fixed in 2.0.0.648-39.el7_9.1 - Upgrade
Upgrade
redhat/ruby-tcltkto a version that resolves this vulnerability.Fixed in 2.0.0.648-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygem-minitestto a version that resolves this vulnerability.Fixed in 4.3.2-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygem-raketo a version that resolves this vulnerability.Fixed in 0.9.6-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygems-develto a version that resolves this vulnerability.Fixed in 2.0.14.1-39.el7_9.1 - Upgrade
Upgrade
redhat/rubyto a version that resolves this vulnerability.Fixed in 2.0.0.648-39.el7_9.1 - Upgrade
Upgrade
redhat/ruby-irbto a version that resolves this vulnerability.Fixed in 2.0.0.648-39.el7_9.1 - Upgrade
Upgrade
redhat/ruby-libsto a version that resolves this vulnerability.Fixed in 2.0.0.648-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygem-bigdecimalto a version that resolves this vulnerability.Fixed in 1.2.0-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygem-io-consoleto a version that resolves this vulnerability.Fixed in 0.4.2-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygem-jsonto a version that resolves this vulnerability.Fixed in 1.7.7-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygem-psychto a version that resolves this vulnerability.Fixed in 2.0.0-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygem-rdocto a version that resolves this vulnerability.Fixed in 4.0.0-39.el7_9.1 - Upgrade
Upgrade
redhat/rubygemsto a version that resolves this vulnerability.Fixed in 2.0.14.1-39.el7_9.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:37397?
The severity of RHSA-2026:37397 is high, rated at 7.
What vulnerabilities are addressed in RHSA-2026:37397?
RHSA-2026:37397 addresses a command injection vulnerability in ruby/net-imap, specifically CVE-2026-42258.
How do I fix RHSA-2026:37397?
To fix RHSA-2026:37397, update to the latest version of Ruby as specified in the security advisory.
Which software packages are affected by RHSA-2026:37397?
The affected software packages include redhat/ruby, redhat/ruby-debuginfo, redhat/ruby-devel, redhat/ruby-libs, redhat/ruby-tcltk, redhat/rubygem-bigdecimal, redhat/rubygem-io-console, and redhat/rubygem-json.
What is CVE-2026-42258 in relation to RHSA-2026:37397?
CVE-2026-42258 is an IMAP command injection vulnerability that can occur via symbolic arguments in the ruby/net-imap library.