Critical Path Traversal Vulnerabilities in rubygem-yard for Fedora 43 and 44

Critical Path Traversal Vulnerabilities in rubygem-yard for Fedora 43 and 44

First seen 5 Jun 2026, 12:10 UTC Linuxsecurity 98% similarity 70.5

Article Content

Browse articles
ThreatCluster

On June 5, 2026, Fedora released updates addressing critical path traversal vulnerabilities in the rubygem-yard documentation tool. The vulnerabilities were backported from versions 0.9.41 and 0.9.44 and affect Fedora 43 and 44 systems. Users are advised to upgrade to the patched versions to mitigate potential exploitation risks. The vulnerabilities could allow unauthorized access to sensitive files, posing a significant risk to affected systems. The updates were announced by Mamoru Tasaka on May 28, 2026, and are available through the 'dnf' update program. The affected versions are 0.9.40-2 for Fedora 44 and 0.9.37-5 for Fedora 43. Administrators are urged to apply the updates promptly to ensure system security.

Key Points: • Critical path traversal vulnerabilities identified in rubygem-yard for Fedora 43 and 44. • Updates backported from versions 0.9.41 and 0.9.44 to address the issues. • Users must upgrade to patched versions to prevent unauthorized file access.

ThreatCluster AI

Timeline

2026-05-28
Backporting of fixes initiated
Mamoru Tasaka backported fixes for path traversal vulnerabilities in rubygem-yard for Fedora 43 and 44.
Linuxsecurity
2026-06-05
Updates released for Fedora 43 and 44
Fedora announced updates for rubygem-yard, addressing critical vulnerabilities affecting both versions.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story