Double Free in Ruby - CVE-2022-28738

 

Double Free in Ruby - CVE-2022-28738

Published: April 12, 2022


Vulnerability identifier: #VU62080
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28738
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in Regexp compilation process in Ruby. A remote attacker can pass specially crafted data to the application, trigger a double free error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Ruby
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Linux
Slackware Linux
Ubuntu
openEuler
Fedora
cflinuxfs3
Red Hat Software Collections
rh-ruby30-ruby (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rubygem-net-telnet
rubygem-rss
rubygem-xmlrpc
rubygem-abrt
rubygem-abrt-doc
rubygem-io-console
rubygem-mysql2
rubygem-mysql2-doc
rubygem-typeprof
rubygem-power_assert
rubygem-did_you_mean
rubygem-pg
rubygem-pg-doc
rubygem-bigdecimal
rubygem-irb
rubygem-rbs
rubygem-json
rubygem-openssl
rubygem-bundler
ruby2.5 (Ubuntu package)
libruby2.5 (Ubuntu package)
ruby-help
ruby-irb
ruby-debugsource
ruby-debuginfo
ruby-devel
ruby
ruby2.7 (Ubuntu package)
libruby2.7 (Ubuntu package)
rubygems-devel
rubygems
rubygem-psych
ruby-libs
ruby-default-gems
ruby-doc
ruby (Red Hat package)
rubygem-rexml
rubygem-test-unit
rubygem-minitest
rubygem-rdoc
rubygem-rake
JD Edwards EnterpriseOne Tools
Isolation Segment
VMware Tanzu Application Service for VMs
ruby3.0 (Ubuntu package)
libruby3.0 (Ubuntu package)

How to mitigate CVE-2022-28738

Install updates from vendor's website.

Ruby - addressed in versions 3.0.4, 3.1.2
cflinuxfs3 - update to 0.303.0
rh-ruby30-ruby (Red Hat package) - update to 3.0.4-149.el7
JD Edwards EnterpriseOne Tools - update to 9.2.7.2
rubygem-net-telnet - update to 0.1.1-116
rubygem-rss - update to 0.2.9-141.0.1
rubygem-xmlrpc - update to 0.3.0-116
rubygem-abrt - update to 0.4.0-1
rubygem-abrt-doc - update to 0.4.0-1
rubygem-io-console - update to 0.4.6-116
rubygem-mysql2 - update to 0.5.3-1
rubygem-mysql2-doc - update to 0.5.3-1
rubygem-io-console - update to 0.5.7-141.0.1
rubygem-typeprof - update to 0.15.2-141.0.1
rubygem-power_assert - update to 1.1.1-116
rubygem-did_you_mean - update to 1.2.0-116
rubygem-power_assert - update to 1.2.0-141.0.1
rubygem-pg - update to 1.2.3-1
rubygem-pg-doc - update to 1.2.3-1
rubygem-bigdecimal - update to 1.3.4-116
rubygem-irb - update to 1.3.5-141.0.1
rubygem-rbs - update to 1.4.0-141.0.1
rubygem-json - update to 2.1.0-116
rubygem-openssl - update to 2.1.2-116
rubygem-bundler - update to 2.2.33-141.0.1
ruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.12
libruby2.5 (Ubuntu package) - update to 2.5.1-1ubuntu1.12
rubygem-json - update to 2.5.1-141.0.1
ruby-help - update to 2.5.8-116
ruby-irb - update to 2.5.8-116
ruby-debugsource - update to 2.5.8-116
ruby-debuginfo - update to 2.5.8-116
ruby-devel - update to 2.5.8-116
ruby - update to 2.5.8-116
ruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.7, 2.7.4-1ubuntu3.2
libruby2.7 (Ubuntu package) - addressed in versions 2.7.0-5ubuntu1.7, 2.7.4-1ubuntu3.2
rubygems-devel - update to 2.7.6-116
rubygems - update to 2.7.6-116
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.15, 2.13.7
rubygem-bigdecimal - update to 3.0.0-141.0.1
ruby3.0 (Ubuntu package) - update to 3.0.2-7ubuntu2.1
libruby3.0 (Ubuntu package) - update to 3.0.2-7ubuntu2.1
rubygem-psych - update to 3.0.2-116
ruby-devel - update to 3.0.4-141.0.1
ruby - update to 3.0.4-141.0.1
ruby-libs - update to 3.0.4-141.0.1
ruby-default-gems - update to 3.0.4-141.0.1
ruby-doc - update to 3.0.4-141.0.1
ruby - addressed in versions 3.0.4-153.fc34, 3.0.4-153.fc35, 3.1.2-164.fc36
ruby (Red Hat package) - update to 3.0.4-160.el9_0
rubygem-rexml - update to 3.2.5-141.0.1
rubygem-test-unit - update to 3.2.7-116
rubygems-devel - update to 3.2.33-141.0.1
rubygems - update to 3.2.33-141.0.1
rubygem-psych - update to 3.3.2-141.0.1
rubygem-test-unit - update to 3.3.7-141.0.1
rubygem-minitest - update to 5.10.3-116
rubygem-minitest - update to 5.14.2-141.0.1
rubygem-rdoc - update to 6.0.1.1-116
rubygem-rdoc - update to 6.3.3-141.0.1
rubygem-rake - update to 12.3.0-116
rubygem-rake - update to 13.0.3-141.0.1

External References

Related Security Bulletins