Debian Patches

Status for ruby-oj/3.14.2-1+deb12u1

Patch Description Author Forwarded Bugs Origin Last update
01_dont_mess_with_loadpath.patch do not mess with $LOAD_PATH this is not at all needed for the tests Cédric Boutillier <boutil@debian.org> not-needed 2017-09-30
03_find_test_helper.patch add relative path so that some tests can finally find test/helper.rb Cédric Boutillier <boutil@debian.org> no 2016-06-01
CVE-2026-oj-security-ec368db.patch backport of upstream stack/extreme-size security fixes (ec368db / #1014) Backport C security fixes from upstream commit ec368db (v3.17.2) covering
CVE-2026-54502 and CVE-2026-54896 through CVE-2026-54903.
.
Includes CVE-2026-54902 saj2.c mark() fix: always rb_gc_mark SAJ stack keys
(drop if (!cache_keys) guard). Upstream ec368db claimed the SAJ long-key UAF
fixed but omitted this hunk; folded here rather than a separate patch.
.
Keep oj_rxclass_match(int len) unchanged for ABI; gate call sites with
INT_MAX before casting. parser_parse freezes an rb_str_dup copy, never the
caller string. On 3.14.2 that function uses DATA_PTR rather than
TypedData_Get_Struct. Dropped non-security hunks: CHANGELOG, version.rb,
notes, safe.c.
not-needed https://github.com/ohler55/oj/commit/ec368dbe936ef0104b782e4b0f67b17d6c7276f7 2026-09-26
CVE-2026-oj-security-bbde91a.patch backport of upstream intern.c / fast.c security fixes (bbde91a / #1015) Backport C security fixes from upstream commit bbde91a (v3.17.3) covering
CVE-2026-54500 and CVE-2026-54592: correct rb_intern3 buffer pointer in
form_attr, and add DepthError / where-- in doc_each_child.
not-needed https://github.com/ohler55/oj/commit/bbde91a679728f94c4492ebc3683f4fa3309049f 2026-09-26

All known versions for source package 'ruby-oj'

Links