Debian Patches
Status for ruby-rack/2.2.22-0+deb12u2
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| skip-random-failure.patch | Skip random failure. | Utkarsh Gupta <utkarsh@debian.org> | not-needed | 2020-04-09 | ||
| 0002-Make-tests-pass-on-hosts-that-have-no-ipv4-connectiv.patch | Make tests pass on hosts that have no ipv4 connectivity This is a backport of the patch sent upstream. |
Antonio Terceiro <terceiro@debian.org> | yes | 2021-02-27 | ||
| skip-unreadable-dir-test.patch | skip unreadable directories test this test failed on reprotest due to reprotest run as root. see: https://salsa.debian.org/salsa-ci-team/pipeline/-/issues/160 |
HIGUCHI Daisuke (VDR dai) <dai@debian.org> | not-needed | |||
| CVE-2026-26961.patch | Raise error for multipart requests with multiple boundary parameters RFC 1341 specifies there should be a single boundary parameter. Requests with multiple boundary parameters are unlikely to be legitimate, and likely are attempts to exploit parsing differences between rack and web application firewalls. * Disallow whitespace between boundary and = when parsing multipart boundaries Rack has historically not accepted these. To avoid security issues when parsing multiple boundaries, check for boundary cases that may have whitespace, but explicitly disallow the parsing if there is whitespace. |
Samuel Williams <samuel.williams@oriontransfer.co.nz> | no | 2026-03-31 | ||
| CVE-2026-34230.patch | Avoid O(n^2) algorithm in Rack::Utils.select_best_encoding If a wildcard has already been seen as an acceptable encoding, ignore additional wildcards. Other improvements while here: * Only process up to 16 encodings. * Improve efficiency of candidate sorting. Add tests for: * Lower but non-zero wildcard priority * Multiple wildcards with different priorities |
Samuel Williams <samuel.williams@oriontransfer.co.nz> | no | 2026-03-31 | ||
| CVE-2026-34763.patch | Root directory disclosure via unescaped regex interpolation in `Rack::Directory`. Escape the root path before interpolating into a regular expression, preventing RegexpError when the root contains metacharacters and avoiding path disclosure when regex silently mismatches. |
Haruki Oyama <harukioyama0409@gmail.com> | no | 2026-03-30 | ||
| CVE-2026-34785.patch | Fix root prefix bug in Rack::Static This is similar to the fix of CVE-2026-22860 for Rack::Directory. |
Jeremy Evans <code@jeremyevans.net> | no | 2026-03-05 | ||
| CVE-2026-34786.patch | Fix `header_rules` bypass via URL-encoded paths. Decode path once in applicable_rules before matching, fixing: - URL-encoded paths bypassing :fonts, Array, and Regexp header rules. - Path mutation across rules when String rule unescapes inside find_all. - Array rule values interpolated into regexp without Regexp.escape. |
haruki0409 <76884995+haruki0409@users.noreply.github.com> | no | 2026-03-22 | ||
| CVE-2026-34826.patch | Use a default limit of 100 byte ranges Allow exceeding this limit by passing max_ranges keyword argument. If the limit is exceeded, return nil, treating the request as not requesting ranges. This seems better than returning [], which would treat the request as requesting no ranges. We use [] when the total size exceeds the size of the file, as such case is obviously a problem. However, a request with more than the given number of ranges is not obviously a problem. |
Jeremy Evans <code@jeremyevans.net> | no | 2026-03-12 | ||
| CVE-2026-34829.patch | Add Content-Length size check in Rack::Multipart::Parser Compare the declared `Content-Length` against a configurable maximum (`PARSER_BYTESIZE_LIMIT`) before any parsing begins. If it exceeds the limit, raise an exception immediately. |
Lio <bentnt1982@gmail.com> | no | 2026-03-08 | ||
| CVE-2026-34830.patch | Only do a simple substitution on the x-accel-mapping paths Mention the substitution is case insensitive in the documentation, since if the file system is case sensitive, this would be unexpected. |
Jeremy Evans <code@jeremyevans.net> | no | 2026-03-10 | ||
| CVE-2026-34831.patch | Use `String#bytesize` for `Content-Length` in error responses. `String#size` returns character count, not byte count. For responses containing multi-byte UTF-8 characters, this produces an incorrect `Content-Length` value, violating RFC 9110 Section 8.6. |
Samuel Williams <samuel.williams@oriontransfer.co.nz> | no | 2026-04-01 |
All known versions for source package 'ruby-rack'
- 3.2.6-3 (sid)
- 3.2.6-2 (forky)
- 3.1.20-0+deb13u1 (trixie-security, trixie)
- 2.2.22-0+deb12u2 (bookworm-security)
- 2.2.22-0+deb12u1 (bookworm)
