Red Hat Product Errata RHSA-2026:34076 - Security Advisory Issued: 2026-07-01 Updated: 2026-07-01 RHSA-2026:34076 - Security Advisory Overview Updated Packages Synopsis Important: ruby:2.5 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the ruby:2.5 module is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258) net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2468498 - CVE-2026-42258 ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments BZ - 2468499 - CVE-2026-42246 net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS CVEs CVE-2026-42246 CVE-2026-42258 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 SRPM ruby-2.5.9-112.module+el8.8.0+24452+e70e99ef.src.rpm SHA-256: bf86fb50f4ea735138a3c0b0c2569bb0c8c5c3f04075eb4d72c3441ab1e1b824 rubygem-abrt-0.3.0-4.module+el8.1.0+3656+f80bfa1d.src.rpm SHA-256: d92c862b65872af7f701367225dc4c9ea799161e19594a7fbc6fa0e19bd2e667 rubygem-bson-4.3.0-2.module+el8.1.0+3656+f80bfa1d.src.rpm SHA-256: 8abe79db0675e5019fbdffd7aef41e9f09810aa30671c445b75dcce54028661a rubygem-bundler-1.16.1-4.module+el8.6.0+14229+2452087f.src.rpm SHA-256: 710cb858c1b2a0d13936146822a43ba83c5bc3b832760fe324561cc43d0ff846 rubygem-mongo-2.5.1-2.module+el8.1.0+3656+f80bfa1d.src.rpm SHA-256: 5b8d89427998167d5c2f9e7a546f7c5dde349f97463935bf40e06130e5383b63 rubygem-mysql2-0.4.10-4.module+el8.1.0+3656+f80bfa1d.src.rpm SHA-256: 7bd7206950c3bdbd8c81073410e7912f0dc35fc319fb2ee084786e446056587a rubygem-pg-1.0.0-2.module+el8.1.0+3656+f80bfa1d.src.rpm SHA-256: 5e71aa5e93b054478e1f399862d6c8030cd459fe8ff8f5369d5660779efded04 x86_64 ruby-2.5.9-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: 7728af80c3b444411476ae5ac1a0c558afe7bfe3b8e49340b6a257621821c652 ruby-2.5.9-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 37140104a0fc29b201fa939411ef9290982eab520880a99b7bec98f63b1ebe25 ruby-debuginfo-2.5.9-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: 710225662971a6ea16ade1550f707f45b986e65047e35e0714511ab386990961 ruby-debuginfo-2.5.9-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: b3e1349a57408f17536a68a53fe5f08571c76cfade1cb393d1a3dedc0c9c3875 ruby-debugsource-2.5.9-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: 1519928e90ea4e4adb7418b42f5a2761c45414ee4539577d7add5d6bf325a426 ruby-debugsource-2.5.9-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 6eca5ef1da492473c16bd371a5f2ed48621427388f3a5be5c01a5d4f9be6df67 ruby-devel-2.5.9-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: 085ee5bc11ac91204a3c05fee432617c2f4ace8c85bbb56c126220f1e4648e6b ruby-devel-2.5.9-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: c3d8fe8d788958f2bac1f4e65ce3979f8e2e95643d987f86b5cc7f2c39dd4c87 ruby-doc-2.5.9-112.module+el8.8.0+24452+e70e99ef.noarch.rpm SHA-256: e44acdb077fc1db4b6656d17bb6f085e87df5027234dc80b740b9965e47e81ca ruby-irb-2.5.9-112.module+el8.8.0+24452+e70e99ef.noarch.rpm SHA-256: 7c2642a69921feb011307f108fbe37939aa09520fffd4a33222f6ca2970449bd ruby-libs-2.5.9-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: 761b0c5514c57aab6155e00901fb962929bf2752cf32b9eab17458eda7987a06 ruby-libs-2.5.9-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 16cc3a57a74ca9b4cd1a28ddde8ca2d786b6568098dedf9930821465afb50ece ruby-libs-debuginfo-2.5.9-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: a832f89ddd82de0ff93d214e35a86d8445f5451772ef25a1a1cfa5e35ac96d08 ruby-libs-debuginfo-2.5.9-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: d55b34fd9dfa1b9c8af982394830d92c51031922b0fdafb69a406257df410c93 rubygem-abrt-0.3.0-4.module+el8.1.0+3656+f80bfa1d.noarch.rpm SHA-256: 2579312600c5f242ff8edbf3b44b3d444962429ad40c17a28ce16500c798d860 rubygem-abrt-doc-0.3.0-4.module+el8.1.0+3656+f80bfa1d.noarch.rpm SHA-256: 4526c3514005042da89bd0884d0404b154ffba64b54112453269e4369b741d4c rubygem-bigdecimal-1.3.4-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: efb73d9e77102988132202654151e422960100ab62ef21db1b0a3c2da7fd4f51 rubygem-bigdecimal-1.3.4-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 9a69aa927ba13d481b6b838a7f185e716d06f9ac7fc6c076522e03a6339cb54c rubygem-bigdecimal-debuginfo-1.3.4-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: cbf5a3b527d155501c5669f934370089bc2cbf8ae1c891b3d8fe8cce90dc2d64 rubygem-bigdecimal-debuginfo-1.3.4-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 864ea380e3c1b61df9cf2510537562df58fe553ef2ce79e363096272f08bc536 rubygem-bson-4.3.0-2.module+el8.1.0+3656+f80bfa1d.x86_64.rpm SHA-256: 4f76f2ea9dc8fffd76a17f020d4bb59ce78adf103f54e6b915f42ae2ff7cb9e4 rubygem-bson-debuginfo-4.3.0-2.module+el8.1.0+3656+f80bfa1d.x86_64.rpm SHA-256: d0f9f0a8ba5d97919ab1db49ea0414cb20a11abbcf11e6bd006d7b447230248a rubygem-bson-debugsource-4.3.0-2.module+el8.1.0+3656+f80bfa1d.x86_64.rpm SHA-256: d217b074bb416f3896a467c860e3c1bba0308eb5a31b2fb10d07e1161e18a928 rubygem-bson-doc-4.3.0-2.module+el8.1.0+3656+f80bfa1d.noarch.rpm SHA-256: 9e2077a81214adffe1f0df18008e65f1ff10c65d61a11ef221b4ee2c94d4d842 rubygem-bundler-1.16.1-4.module+el8.6.0+14229+2452087f.noarch.rpm SHA-256: 5f81bc135fcac8c996c1a64b3422c4b2f38f6f94b8d86507678e1ef11c89a962 rubygem-bundler-doc-1.16.1-4.module+el8.6.0+14229+2452087f.noarch.rpm SHA-256: 516863418d04fb0bb1103ef32539303f90c3bd5f90f23146f7e72d2b3d342e91 rubygem-did_you_mean-1.2.0-112.module+el8.8.0+24452+e70e99ef.noarch.rpm SHA-256: 84daed93bd629ede55bf8337f064a92ddb0fd5c5779e7d829ba35d955d257e80 rubygem-io-console-0.4.6-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: ea8ed9439aca47358f07c8f5e3057cd9abd46eb9e22149177c9a46998febbb2e rubygem-io-console-0.4.6-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: b1f0a5b52fc1ecd82a65f805a29ef010906934891f8784366d67919af0adc18a rubygem-io-console-debuginfo-0.4.6-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: f5682c1e350b9340650b9b44412af04c39a9b574ffc7d30f1a17b96c350dde58 rubygem-io-console-debuginfo-0.4.6-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 18bcc19c0eb4ed9c3c92d940d11324b390d28a83b86d73664ef09e6f8688f60e rubygem-json-2.1.0-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: f9adc032225d41ea6c8aae962d119bb10a100f24bccb5f4b31722666431abd8b rubygem-json-2.1.0-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: da923a1c4b1524e964a2a51eb249ca4705039aeee12cbba83894b0450c6c65b5 rubygem-json-debuginfo-2.1.0-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: d40e72dab8973100ac219ec66c51e92f968eccba41c85980e82841b1ae3d8390 rubygem-json-debuginfo-2.1.0-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 27af5aacd56461043bab1e3324b0a684b3465d623593b7f3989ea8ca475192c2 rubygem-minitest-5.10.3-112.module+el8.8.0+24452+e70e99ef.noarch.rpm SHA-256: fe19e5f43c7bdb67ceb337630dfb97c460a5de8de3abb9ea6b9e6ea0e97c2c69 rubygem-mongo-2.5.1-2.module+el8.1.0+3656+f80bfa1d.noarch.rpm SHA-256: 9b5c365e81f801d82f196b89b60184d6135ecd163611738cc07a8f75f1a9b466 rubygem-mongo-doc-2.5.1-2.module+el8.1.0+3656+f80bfa1d.noarch.rpm SHA-256: cba0a8b1b342a3a11801c21a9c403b4c028a290cf45c1589b16a191c7e8ba90f rubygem-mysql2-0.4.10-4.module+el8.1.0+3656+f80bfa1d.x86_64.rpm SHA-256: a43c894e595f14bdabe42cbc68bdfe3e6a3c63dba941d5b0fcd65f143454d36f rubygem-mysql2-debuginfo-0.4.10-4.module+el8.1.0+3656+f80bfa1d.x86_64.rpm SHA-256: e5cf33cab75e90626c7fd72e7e61aa0394111bc2938e2c00b5c30dc44405e80b rubygem-mysql2-debugsource-0.4.10-4.module+el8.1.0+3656+f80bfa1d.x86_64.rpm SHA-256: aef4d0858f00f3a9c9fc606d8d1c4ebfc5fd20668f0614f86cb17a6defa54bc7 rubygem-mysql2-doc-0.4.10-4.module+el8.1.0+3656+f80bfa1d.noarch.rpm SHA-256: 1d25f8d911a95b4abc5649e738ef1bd649ecf60f1d7fca5f444ec154765620d3 rubygem-net-telnet-0.1.1-112.module+el8.8.0+24452+e70e99ef.noarch.rpm SHA-256: 46486f45492d22c3642a927ffea5c83789a0e6ce219ee3f5187da924b9c1bd55 rubygem-openssl-2.1.2-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: 5b9bc2bc3bbfb27d2fae9d429f830cf3bcce4a25cf57c8203478ba49280f369b rubygem-openssl-2.1.2-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: f1341eaaee8c94a987f3e754190f07bd9a084c31edf96d85d241199c9c33a87c rubygem-openssl-debuginfo-2.1.2-112.module+el8.8.0+24452+e70e99ef.i686.rpm SHA-256: b0f1107f6e99e11feb4b9d2add721c9d0fe486362d78d7727eb40d7ee610c4eb rubygem-openssl-debuginfo-2.1.2-112.module+el8.8.0+24452+e70e99ef.x86_64.rpm SHA-256: 6ba92a4d3eba736ac1dce176ad1e23dd2e58fddc415077418bc174543e9aa14e
This security update addresses two vulnerabilities in the Ruby `net-imap` library: CVE-2026-42258 (CVSS 5.3 MEDIUM) allows IMAP command injection via symbol arguments, and CVE-2026-42246 (CVSS 7.4 HIGH) enables information disclosure via a man-in-the-middle attack that can bypass TLS. The affected version ranges are `net-imap` < 0.3.10, >= 0.4.0 < 0.4.24, >= 0.5.0 < 0.5.14, and >= 0.6.0 < 0.6.4. The fixed versions are 0.3.10, 0.4.24, 0.5.14, and 0.6.4, respectively.