Rapid7

vulnerability

Ubuntu: USN-3365-1 (CVE-2016-2339): Ruby vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Jan 6, 2017
Added
Jul 26, 2017
Modified
Apr 16, 2026

Description

An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array size after mentioned allocation and cause heap overflow.

Solutions

ubuntu-upgrade-libruby1-9-1ubuntu-upgrade-libruby2-0ubuntu-upgrade-libruby2-3ubuntu-upgrade-ruby1-9-1ubuntu-upgrade-ruby2-0ubuntu-upgrade-ruby2-3
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.