Unrated severityNVD Advisory· Published May 9, 2022· Updated Aug 3, 2024
CVE-2022-28738
CVE-2022-28738
Description
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.
Affected products
31- Ruby/Rubydescription
- osv-coords30 versionspkg:bitnami/rubypkg:bitnami/ruby-minpkg:rpm/almalinux/rubypkg:rpm/almalinux/ruby-default-gemspkg:rpm/almalinux/ruby-develpkg:rpm/almalinux/ruby-docpkg:rpm/almalinux/rubygem-abrtpkg:rpm/almalinux/rubygem-abrt-docpkg:rpm/almalinux/rubygem-bigdecimalpkg:rpm/almalinux/rubygem-bundlerpkg:rpm/almalinux/rubygem-io-consolepkg:rpm/almalinux/rubygem-irbpkg:rpm/almalinux/rubygem-jsonpkg:rpm/almalinux/rubygem-minitestpkg:rpm/almalinux/rubygem-mysql2pkg:rpm/almalinux/rubygem-mysql2-docpkg:rpm/almalinux/rubygem-pgpkg:rpm/almalinux/rubygem-pg-docpkg:rpm/almalinux/rubygem-power_assertpkg:rpm/almalinux/rubygem-psychpkg:rpm/almalinux/rubygem-rakepkg:rpm/almalinux/rubygem-rbspkg:rpm/almalinux/rubygem-rdocpkg:rpm/almalinux/rubygem-rexmlpkg:rpm/almalinux/rubygem-rsspkg:rpm/almalinux/rubygemspkg:rpm/almalinux/rubygems-develpkg:rpm/almalinux/rubygem-test-unitpkg:rpm/almalinux/rubygem-typeprofpkg:rpm/almalinux/ruby-libs
>= 3.0.0, < 3.0.4+ 29 more
- (no CPE)range: >= 3.0.0, < 3.0.4
- (no CPE)range: >= 3.0.0, < 3.0.4
- (no CPE)range: < 3.0.4-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.0.4-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.0.4-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.0.4-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 0.4.0-1.module_el8.5.0+2595+0c654ebc
- (no CPE)range: < 0.4.0-1.module_el8.5.0+2595+0c654ebc
- (no CPE)range: < 3.0.0-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 2.2.33-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 0.5.7-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 1.3.5-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 2.5.1-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 5.14.2-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 0.5.3-1.module_el8.5.0+2595+0c654ebc
- (no CPE)range: < 0.5.3-1.module_el8.5.0+2595+0c654ebc
- (no CPE)range: < 1.2.3-1.module_el8.5.0+2595+0c654ebc
- (no CPE)range: < 1.2.3-1.module_el8.5.0+2595+0c654ebc
- (no CPE)range: < 1.2.0-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.3.2-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 13.0.3-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 1.4.0-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 6.3.3-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.2.5-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 0.2.9-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.2.33-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.2.33-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.3.7-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 0.15.2-141.module_el8.6.0+3263+41cde0c0
- (no CPE)range: < 3.0.4-141.module_el8.6.0+3263+41cde0c0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.