Security update for ruby3.4
This update for ruby3.4 fixes the following issues - CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011). - CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in 'raw' argument (bsc#1268337). - CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338). - CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339). - CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034). Changes for ruby3.4: - Update to 3.4.10: - bundling net-imap 0.5.15.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ruby3.4 fixes the following issues - CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011). - CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in 'raw' argument (bsc#1268337). - CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338). - CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339). - CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034). Changes for ruby3.4: - Update to 3.4.10: - bundling net-imap 0.5.15.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1268011
- https://bugzilla.suse.com/1268337
- https://bugzilla.suse.com/1268338
- https://bugzilla.suse.com/1268339
- https://bugzilla.suse.com/1270034
- https://www.suse.com/security/cve/CVE-2025-61594
- https://www.suse.com/security/cve/CVE-2026-42258
- https://www.suse.com/security/cve/CVE-2026-47240
- https://www.suse.com/security/cve/CVE-2026-47241
- https://www.suse.com/security/cve/CVE-2026-47242
- https://www.suse.com/support/update/announcement/2026/suse-su-20263090-1/