Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Recent updates for Oracle Linux address critical vulnerabilities in Ruby affecting versions 2.5, 3.3, and 4.0. Key issues include a code execution flaw (CVE-2026-41316) and denial of service vulnerabilities (CVE-2026-42245, CVE-2026-33210) that could be exploited via crafted IMAP responses and forma...
Two critical vulnerabilities were discovered in Ruby affecting the Net::IMAP client and Zlib::GzipReader. CVE-2026-42258 allows remote attackers to inject arbitrary IMAP commands via CRLF sequences, while CVE-2026-27820 can lead to a buffer overflow through crafted gzip streams. These vulnerabilitie...
On October 1, 2026, Oracle released security updates for Ruby in Oracle Linux 9 and 10, addressing multiple memory exhaustion vulnerabilities. The most significant flaw, CVE-2026-80212, affects Ruby versions 3.0.7 and 4.0.6, allowing for potential denial of service through unknown DNS resource types...