{"schema_version":"1.7.5","id":"SUSE-SU-2026:3090-1","published":"2026-07-17T06:13:22Z","modified":"2026-07-18T08:45:08.623601243Z","related":["CVE-2025-61594","CVE-2026-42258","CVE-2026-47240","CVE-2026-47241","CVE-2026-47242"],"upstream":["CVE-2025-61594","CVE-2026-42258","CVE-2026-47240","CVE-2026-47241","CVE-2026-47242"],"summary":"Security update for ruby3.4","details":"This update for ruby3.4 fixes the following issues\n\n- CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011).\n- CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in 'raw' argument (bsc#1268337).\n- CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338).\n- CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339).\n- CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034).\n\nChanges for ruby3.4:\n\n- Update to 3.4.10: \n\n  - bundling net-imap 0.5.15.\n","affected":[{"package":{"name":"ruby3.4","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/ruby3.4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.10-150700.3.4.1"}]}],"ecosystem_specific":{"binaries":[{"libruby3_4-3_4":"3.4.10-150700.3.4.1","ruby3.4":"3.4.10-150700.3.4.1","ruby3.4-devel":"3.4.10-150700.3.4.1","ruby3.4-devel-extra":"3.4.10-150700.3.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3090-1.json"}},{"package":{"name":"ruby3.4","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/ruby3.4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.10-150700.3.4.1"}]}],"ecosystem_specific":{"binaries":[{"ruby3.4-doc":"3.4.10-150700.3.4.1","ruby3.4-doc-ri":"3.4.10-150700.3.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3090-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263090-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268337"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268338"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268339"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-61594"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42258"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47240"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47241"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47242"}]}