An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array size after mentioned allocation and cause heap overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby | May 8, 2019 | Jan 6, 2017 |
| Debian | — | Upgrade ruby2.3 | Feb 20, 2019 | Jan 6, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade rubyUpgrade ruby-irbUpgrade rubygemsUpgrade rubygem-rdocUpgrade rubygem-jsonUpgrade ruby-libsUpgrade rubygem-psychUpgrade rubygem-bigdecimalUpgrade rubygem-io-console | Nov 30, 2017 | Jan 6, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ruby-irbUpgrade rubyUpgrade ruby-libs | Nov 30, 2017 | Jan 6, 2017 |
| Oracle Solaris | — | Upgrade runtime/ruby-23 to version 2.3.8-11.4.6.0.1.1.0 on Solaris 11.4Upgrade runtime/ruby-23/ruby-tk to version 2.3.8-11.4.6.0.1.1.0 on Solaris 11.4 | Feb 20, 2019 | Jan 6, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 14, 2016 |
| Suse | — | Upgrade yast2-ruby-bindingsUpgrade ruby2.1Upgrade ruby2.1-stdlibUpgrade ruby2.1-develUpgrade libruby2_1-2_1 | Apr 5, 2017 | Jan 6, 2017 |
| Ubuntu | — | Upgrade ruby2.0Upgrade libruby1.9.1Upgrade ruby1.9.1Upgrade libruby2.3Upgrade ruby2.3Upgrade libruby2.0 | Jul 26, 2017 | Jan 6, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub