Project

General

Profile

Actions

Misc #20685

open

Ruby 3.2.4 tag mentions unrelated changes (CVE-2024-27280)

Added by kenhys (Kentaro Hayashi) 13 days ago. Updated 13 days ago.

Status:
Open
Assignee:
-
[ruby-core:118892]

Description

Problem

According to https://github.com/ruby/ruby/releases/tag/v3_2_4,
it mentions "CVE-2024-27280: Buffer overread vulnerability in StringIO"
as a security fix, but https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/
explicitly describe that the following:

This vulnerability is not affected StringIO 3.0.3 and later, and Ruby 3.2.x and later.

so, it is a bit strange that CVE-2023-27280 was mentioned as security fix for 3.2.x, IMHO.

Please correct me if I'm wrongly interpreted it.

Expected

The problematic description was removed from tags and release note.

Additional Information

Updated by nagachika (Tomoyuki Chikanaga) 13 days ago

Thank you for your greate catch! You are totally right. ruby-3.2 seriese contains stringio-3.0.4 from the beginning.

I remove the CVE reference in the GitHub release page now. https://github.com/ruby/ruby/releases/tag/v3_2_4

I will also remove the links in the release announce pages in www.ruby-lang.org afterward.

Actions

Also available in: Atom PDF

Like0
Like0