CVE-2022-28738
Summary
| CVE | CVE-2022-28738 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-09 18:15:00 UTC |
| Updated | 2024-01-24 05:15:00 UTC |
| Description | A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations. |
Risk And Classification
Problem Types: CWE-415
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-28738: Double free in Regexp compilation | CONFIRM | www.ruby-lang.org | |
| CVE-2022-28738 | MISC | security-tracker.debian.org | |
| Ruby: Multiple vulnerabilities (GLSA 202401-27) — Gentoo security | security.gentoo.org | ||
| May 2022 Ruby Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| HackerOne | MISC | hackerone.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160095 Oracle Enterprise Linux Security Update for ruby:3.0 (ELSA-2022-6450)
- 160103 Oracle Enterprise Linux Security Update for ruby (ELSA-2022-6585)
- 198817 Ubuntu Security Notification for Ruby Vulnerabilities (USN-5462-1)
- 240659 Red Hat Update for ruby:3.0 security (RHSA-2022:6450)
- 240681 Red Hat Update for ruby security (RHSA-2022:6585)
- 240723 Red Hat Update for rh-ruby30-ruby security (RHSA-2022:6855)
- 282660 Fedora Security Update for ruby (FEDORA-2022-82a9edac27)
- 282661 Fedora Security Update for ruby (FEDORA-2022-8cf0124add)
- 356174 Amazon Linux Security Advisory for ruby : ALASRUBY3.0-2023-002
- 356495 Amazon Linux Security Advisory for ruby : ALAS2RUBY3.0-2023-002
- 502025 Alpine Linux Security Update for ruby
- 502236 Alpine Linux Security Update for ruby
- 504378 Alpine Linux Security Update for ruby
- 690840 Free Berkeley Software Distribution (FreeBSD) Security Update for ruby (f22144d7-bad1-11ec-9cfe-0800270512f4)
- 710844 Gentoo Linux Ruby Multiple Vulnerabilities (GLSA 202401-27)
- 940691 AlmaLinux Security Update for ruby (ALSA-2022:6585)
- 940849 AlmaLinux Security Update for ruby:3.0 (ALSA-2022:6450)
- 960234 Rocky Linux Security Update for ruby:3.0 (RLSA-2022:6450)
- 960532 Rocky Linux Security Update for ruby (RLSA-2022:6585)