[ubuntu/noble-security] ruby-rack 2.2.7-1ubuntu0.7 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Thu Apr 16 16:28:23 UTC 2026
ruby-rack (2.2.7-1ubuntu0.7) noble-security; urgency=medium
* SECURITY UPDATE: Security bypass in multipart parser
- debian/patches/CVE-2026-26961.patch: Disallow boundary whitespace in
lib/rack/multipart/parser.rb
- CVE-2026-26961
* SECURITY UPDATE: Denial of service in select_best_encoding
- debian/patches/CVE-2026-34230.patch: Disregard subsequent wildcards
when an acceptable encoding has been selected in lib/rack/utils.rb
- CVE-2026-34230
* SECURITY UPDATE: Permissive regular expression in Directory
- debian/patches/CVE-2026-34763.patch: Escape root before evaluating regex
in lib/rack/directory.rb
- CVE-2026-34763
* SECURITY UPDATE: Information disclosure in Static
- debian/patches/CVE-2026-34785.patch: Check that paths start with the
static root prefix rather than merely containing them in
lib/rack/static.rb
- CVE-2026-34785
* SECURITY UPDATE: Security bypass in applicable_rules
- debian/patches/CVE-2026-34786.patch: Decode path before parsing to avoid
bypassing header rules in lib/rack/static.rb
- CVE-2026-34786
* SECURITY UPDATE: Denial of service in byte_ranges
- debian/patches/CVE-2026-34826.patch: Add a max_ranges argument to
byte_ranges in lib/rack/utils.rb
- CVE-2026-34826
* SECURITY UPDATE: Denial of service in Parser
- debian/patches/CVE-2026-34829.patch: Set maximum value for
content-length in lib/rack/multipart/parser.rb
- CVE-2026-34829
* SECURITY UPDATE: Permissive regular expression in map_accel_path
- debian/patches/CVE-2026-34830.patch: Escape X-Accel-Mapping before
interpreting as regular expression in lib/rack/sendfile.rb
- CVE-2026-34830
* SECURITY UPDATE: Improper handling of length in fail
- debian/patches/CVE-2026-34831.patch: Set content-length to byte size
rather than UTF-8 length in lib/rack/files.rb
- CVE-2026-34831
Date: 2026-04-14 23:00:15.608497+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
Signed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/ruby-rack/2.2.7-1ubuntu0.7
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list