Skip to content

Commit eca0ecc

Browse files
authored
Merge pull request #1223 from jasnow/new-branch-name
One new mruby advisory; 1 updated ruby advisory and rad-ignores.sh script @simi - Thanks for taking the time to review and approve this PR.
2 parents 8cfcc07 + 478b63d commit eca0ecc

3 files changed

Lines changed: 93 additions & 5 deletions

File tree

lib/rad-ignores.sh

Lines changed: 45 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -72,8 +72,8 @@ rm -rf gems/commonmarker/GHSA-7vh7-fw88-wj87.yml
7272
# maintainer involvement, and WEBrick's documented scope has excluded
7373
# production use since 2020.
7474
# 7/10/2026: https://github.com/ruby/webrick/issues/198
75-
rm -f gems/webrick/CVE-2024-47220.yml
76-
rm -f gems/webrick/CVE-2026-38969.yml
75+
rm -f gems/webrick/CVE-2024-47220.yml # GHSA-6f62-3596-g6w7
76+
rm -f gems/webrick/CVE-2026-38969.yml # GHSA-h4w6-wx8r-p68v
7777

7878
# https://github.com/Shopify/ruby-lsp/security/advisories/GHSA-2x7g-8mp4-572w
7979
# is a Shopify.ruby-lsp (VS Code Extension), not a Ruby gem.
@@ -116,12 +116,12 @@ rm -f gems/omniauth-saml/GHSA-cgp2-2cmh-pf7x.yml
116116
# https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-76c2-66pg-fj2f
117117
# - https://github.com/pglombardo/PasswordPusher/releases/tag/v2.8.1
118118
# Release 2.8.1; pglombardo/PasswordPusher; RUBY code; Bash Poc; Ruby fix; No CVE
119-
#...
119+
#...
120120
# https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-qfh8-f79c-x86c
121121
# - https://github.com/pglombardo/PasswordPusher/pull/4381
122122
# - https://github.com/pglombardo/PasswordPusher/releases/tag/v2.4.2
123123
# Release 2:4.2 - Ruby rb code; Unreviewed GHSA
124-
#...
124+
#...
125125
# https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-4fwj-m62q-pp47
126126
# Never patched; CVE-2024-56733; Password Pusher; No project references
127127
#...
@@ -174,3 +174,44 @@ rm -f gems/action_text-trix/CVE-2026-73426.yml \
174174

175175
# 8/15/2026: Using GHSA filenames (new policy) instead of CVE filenames.
176176
rm -f gems/kobako/CVE-2026-55107.yml
177+
178+
# "chkr" IGNORE-THEM (2022) advisories (8/21/2026: None in this repo)
179+
# #......................................................................
180+
# # Ruby mentioned
181+
# GHSA-5458-w8p3-f624 - CVE-2017-7642 (mentions ruby but not ruby lang)
182+
# GHSA-hwm5-7hrp-v744 - CVE-2006-6979 (mentions ruby, not ruby lang)
183+
# GHSA-2jww-8ppq-f5qp - CVE-2019-12575 (mentions ruby but not ruby lang)
184+
# #......................................................................
185+
# # DISPUTED
186+
# GHSA-c2xw-j3rw-89x2 DISPUTED - SQL injection vul
187+
# GHSA-rjh4-8mqr-rvr8 DISPUTED - SQL injection vul
188+
# GHSA-vqpc-h5g8-fhrw DISPUTED - SQL injection vul
189+
# GHSA-4w6g-25w8-c8vc DISPUTED - SQL injection vul
190+
# GHSA-6qq6-x75v-fgg7 DISPUTED - openssl extension - CVE-2014-2734
191+
# GHSA-jwh5-q83f-2jjc DISPUTED - WEBrick gem 1.4.2
192+
# #......................................................................
193+
# #NOT RUBY (Ruby Tools)
194+
# GHSA-6r9x-mqf6-jvrp - CVE-2017-1000047 - rbenv (ruby tool)
195+
# GHSA-9j7m-jqrm-mcj3 - CVE-2019-5624 - Rapid7 Metasploit Framework (tool)
196+
# GHSA-rm8f-p7g6-p8p4 - CVE-2009-4079 - (redmine, not ruby lang)
197+
# GHSA-68hg-cfx6-pvhh - CVE-2009-4078 - (redmine, not ruby lang)
198+
# GHSA-xg2h-5xr2-29jw - CVE-2026-59861 - (Microsoft/Kiota Ruby code generator)
199+
# #......................................................................
200+
# # NOT RUBY
201+
# GHSA-qgq2-pf5j-2fvq JAVASCRIPT/Prototype.js
202+
# GHSA-w8r8-w5w4-4w4v - CVE-2014-0160 - openssl - not directly ruby
203+
# https://www.ruby-lang.org/en/news/2014/04/10/severe-openssl-vulnerability
204+
# GHSA-h4xp-827w-ffh7 - CVE-2016-4864 (ho2, not mruby lang)
205+
# GHSA-jmhx-fqfh-838h NOT-RUBY
206+
# CVE-2022-45301 NOT-RUBY
207+
# GHSA-6938-wq9x-9rgg - CVE-2012-1241
208+
# GHSA-6f39-fvhf-c6qr - CVE-2017-11465 (REJECTED)
209+
# GHSA-rc82-v3mm-rhj2 - CVE-2011-3624.yml (REJECTED)
210+
# GHSA-94xx-gq3f-6gw4 - CVE-2026-1097.yml (not ruby)
211+
# #......................................................................
212+
# # Redhat
213+
# GHSA-3fcg-qm7h-hhpw (red hat #3)
214+
# GHSA-gphm-f2cq-m9pv (red hat #2)
215+
# GHSA-w5v4-7h7x-xfvq (red hat #1)
216+
# GHSA-h459-7mrx-8pvc - CVE-2014-0241 (Red hat plugin, not ruby lang)
217+
# GHSA-f29j-vf7h-f9g9 - CVE-2013-1945

rubies/mruby/CVE-2026-1979.yml

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
---
2+
engine: mruby
3+
cve: 2026-1979
4+
ghsa: gxgq-rpmr-r8xr
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-1979
6+
title: Heap-Use-after-Free vulnerability in mruby's mrb_vm_exec function
7+
date: 2026-02-06
8+
description: |
9+
A flaw has been found in mruby up to 3.4.0. This affects the function
10+
mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF
11+
Optimization. Executing a manipulation can lead to use after free.
12+
The attack needs to be launched locally. The exploit has been
13+
published and may be used.
14+
15+
This patch is called e50f15c1c6e131fa7934355eb02b8173b13df415.
16+
It is advisable to implement a patch to correct this issue.
17+
cvss_v2: 4.3
18+
cvss_v3: 5.3
19+
cvss_v4: 1.9
20+
patched_versions:
21+
- ">= 4.0.0"
22+
related:
23+
url:
24+
- https://nvd.nist.gov/vuln/detail/CVE-2026-1979
25+
- https://github.com/mruby/mruby/blob/master/NEWS.md#user-visible-changes-in-mruby40-from-mruby34
26+
- https://github.com/sysfce2/mruby/commit/e50f15c1c6e131fa7934355eb02b8173b13df415
27+
- https://github.com/mruby/mruby/issues/6701
28+
- https://github.com/mruby/mruby/issues/6701#issue-3802609843
29+
- https://github.com/mruby/mruby/issues/6704
30+
- https://github.com/mruby/mruby
31+
- https://vuldb.com/?ctiid.344501
32+
- https://vuldb.com/?id.344501
33+
- https://vuldb.com/?submit.743377
34+
- https://github.com/advisories/GHSA-gxgq-rpmr-r8xr
35+
notes: |
36+
- GHSA advisory is "unreviewed".
37+
- See Iss#6701 is NEWS.md post.
38+
- git tag --contains e50f15c1c6e131fa7934355eb02b8173b13df415
39+
- 4.0.0-rc/rc2/rc3 and 4.0.0

rubies/ruby/CVE-2008-1447.yml

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
---
22
engine: ruby
33
cve: 2008-1447
4+
ghsa: r5r9-27m2-2jg7
45
url: https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
5-
title: ruby -- DNS spoofing vulnerability in resolv.rb
6+
title: ruby - DNS spoofing vulnerability in resolv.rb
67
date: 2008-05-05
78
description: |
89
resolv.rb allow remote attackers to spoof DNS answers. This risk can be
@@ -13,3 +14,10 @@ patched_versions:
1314
- "~> 1.8.6.287"
1415
- "~> 1.8.7.72"
1516
- ">= 1.9.0"
17+
related:
18+
ghsa:
19+
- vwcj-mf69-7rfw
20+
url:
21+
- https://www.cve.org/CVERecord?id=CVE-2008-1447
22+
- https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby
23+
- https://github.com/advisories/GHSA-r5r9-27m2-2jg7

0 commit comments

Comments
 (0)