Debian dla-4716 : libruby2.7 - security update

medium Nessus Plugin ID 331823

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 11 host has packages installed that are affected by multiple vulnerabilities as referenced in the dla-4716 advisory.

- ------------------------------------------------------------------------- Debian LTS Advisory DLA-4716-1 [email protected] https://www.debian.org/lts/security/ Abhijith PA August 04, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : ruby2.7 Version : 2.7.4-1+deb11u6 $bookworm_VERSION CVE ID : CVE-2025-24294 CVE-2025-61594 CVE-2026-27820 CVE-2026-41316


Ruby a popular language was affected by multiple vulnerabilities

CVE-2025-24294

The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.

CVE-2025-61594

Using the + operator to combine URIs, sensitive information like passwords from the original URI can be leaked, violating RFC3986 and making applications vulnerable to credential exposure. URI is a module providing classes to handle Uniform Resource Identifiers.

CVE-2026-27820

A buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity.

CVE-2026-41316

A deserialization vulnerability exists in ERB. Any Ruby application that calls Marshal.load on untrusted data AND has both erb and activesupport loaded is vulnerable to arbitrary code execution.

For Debian 11 bullseye, these problems have been fixed in version 2.7.4-1+deb11u6.

We recommend that you upgrade your ruby2.7 packages.

For the detailed security status of ruby2.7 please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/ruby2.7

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libruby2.7 packages.

See Also

https://packages.debian.org/source/bullseye/ruby2.7

https://security-tracker.debian.org/tracker/CVE-2025-24294

https://security-tracker.debian.org/tracker/CVE-2025-61594

https://security-tracker.debian.org/tracker/CVE-2026-27820

https://security-tracker.debian.org/tracker/CVE-2026-41316

https://security-tracker.debian.org/tracker/source-package/ruby2.7

Plugin Details

Severity: Medium

ID: 331823

File Name: debian_DLA-4716.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/4/2026

Updated: 8/4/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.97

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-27820

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:11.0, p-cpe:/a:debian:debian_linux:libruby2.7, p-cpe:/a:debian:debian_linux:ruby2.7-dev, p-cpe:/a:debian:debian_linux:ruby2.7-doc, p-cpe:/a:debian:debian_linux:ruby2.7

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/4/2026

Vulnerability Publication Date: 7/12/2025

Reference Information

CVE: CVE-2025-24294, CVE-2025-61594, CVE-2026-27820, CVE-2026-41316