Debian Patches
Status for ruby-oj/3.14.2-1+deb12u1
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| 01_dont_mess_with_loadpath.patch | do not mess with $LOAD_PATH this is not at all needed for the tests | Cédric Boutillier <boutil@debian.org> | not-needed | 2017-09-30 | ||
| 03_find_test_helper.patch | add relative path so that some tests can finally find test/helper.rb | Cédric Boutillier <boutil@debian.org> | no | 2016-06-01 | ||
| CVE-2026-oj-security-ec368db.patch | backport of upstream stack/extreme-size security fixes (ec368db / #1014) Backport C security fixes from upstream commit ec368db (v3.17.2) covering CVE-2026-54502 and CVE-2026-54896 through CVE-2026-54903. . Includes CVE-2026-54902 saj2.c mark() fix: always rb_gc_mark SAJ stack keys (drop if (!cache_keys) guard). Upstream ec368db claimed the SAJ long-key UAF fixed but omitted this hunk; folded here rather than a separate patch. . Keep oj_rxclass_match(int len) unchanged for ABI; gate call sites with INT_MAX before casting. parser_parse freezes an rb_str_dup copy, never the caller string. On 3.14.2 that function uses DATA_PTR rather than TypedData_Get_Struct. Dropped non-security hunks: CHANGELOG, version.rb, notes, safe.c. |
not-needed | https://github.com/ohler55/oj/commit/ec368dbe936ef0104b782e4b0f67b17d6c7276f7 | 2026-09-26 | ||
| CVE-2026-oj-security-bbde91a.patch | backport of upstream intern.c / fast.c security fixes (bbde91a / #1015) Backport C security fixes from upstream commit bbde91a (v3.17.3) covering CVE-2026-54500 and CVE-2026-54592: correct rb_intern3 buffer pointer in form_attr, and add DepthError / where-- in doc_each_child. |
not-needed | https://github.com/ohler55/oj/commit/bbde91a679728f94c4492ebc3683f4fa3309049f | 2026-09-26 |
All known versions for source package 'ruby-oj'
- 3.17.7-1 (sid, forky)
- 3.16.3-1+deb13u1 (trixie-proposed-updates, trixie-security)
- 3.16.3-1 (trixie)
- 3.14.2-1+deb12u1 (bookworm-security)
- 3.14.2-1 (bookworm)
