Back Linuxsecurity Ubuntu 22.04 LTS Sinatra Denial of Service Vulnern 2026-8624
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
Sinatra could be made to crash if it received specially crafted network traffic. Software Description: - ruby-sinatra: Ruby web-development dressed in a DSL Details: It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.
Sinatra could be made to crash if it received specially crafted network
Software Description:
- ruby-sinatra: Ruby web-development dressed in a DSL
It was discovered that Sinatra did not properly handle header parsing,
causing ETag generation to hang when given specific input. A remote
attacker could possibly use this issue to cause a denial of service.
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS ruby-sinatra 2.0.8.1-2+deb11u1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS ruby-sinatra 2.0.8.1-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS ruby-sinatra 1.4.8-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS ruby-sinatra 1.4.7-3ubuntu0.1~esm3 Available with Ubuntu Pro After a standard system update you need to restart any applications that use ruby-sinatra to make all the necessary changes.
Ubuntu Security Notice USN-8624-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
