Skip to content
Multiple Ruby Memory Exhaustion Vulnerabilities in Oracle Linux Fixed

Multiple Ruby Memory Exhaustion Vulnerabilities in Oracle Linux Fixed

First seen 1 Oct 2026, 20:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 21:05 UTC
  • •Oracle Linux 9 and 10 Ruby updates released on October 1, 2026.
  • •CVE-2026-80212 allows potential denial of service via memory exhaustion.
  • •Critical vulnerabilities could enable server code execution in self-managed GitLab.

On October 1, 2026, Oracle released security updates for Ruby in Oracle Linux 9 and 10, addressing multiple memory exhaustion vulnerabilities. The most significant flaw, CVE-2026-80212, affects Ruby versions 3.0.7 and 4.0.6, allowing for potential denial of service through unknown DNS resource types. Other vulnerabilities include CVE-2026-42246, which enables information disclosure via MITM attacks, and CVE-2026-42258, allowing command injection through unvalidated Symbol arguments. These vulnerabilities could lead to server code execution, particularly affecting self-managed GitLab instances. Users are urged to upgrade to the patched Ruby versions immediately. The vulnerabilities were disclosed between May and August 2026, with the most fix released on the same day as the advisory.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-20
CVE-2026-33210 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-24
CVE-2026-41316 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-09
Multiple CVEs disclosed
CVE-2026-42246 and CVE-2026-42258 published, affecting Ruby's net-imap functionality.
Linuxsecurity
2026-05-09
CVE-2026-42258 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-09
CVE-2026-42246 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-09
CVE-2026-42245 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-27
CVE-2026-80212 published
CVE-2026-80212 disclosed, highlighting memory exhaustion vulnerabilities in Ruby.
Linuxsecurity
2026-10-01
Oracle releases security updates
Oracle issued patches for Ruby vulnerabilities in Oracle Linux 9 and 10, urging immediate upgrades.
Linuxsecurity

More articles in this cluster (4)

Following this threat?

Track CVE-2026-33210 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Ruby versions are affected?
Ruby versions 3.0.7 and 4.0.6 are affected by the memory exhaustion vulnerabilities.
What should I do to mitigate these vulnerabilities?
Upgrade to the latest patched versions of Ruby as soon as possible to prevent exploitation.
Are these vulnerabilities actively being exploited?
Currently, there are no reports of active exploitation for these vulnerabilities.