Debian Patches
Status for ruby-rack-session/2.1.1-0.1+deb13u1
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| avoid-relative-require-to-lib.patch | Avoid relative require to lib/. | Utkarsh Gupta <utkarsh@debian.org> | no | debian | vendor | 2025-01-30 |
| CVE-2026-39324-reject-unencrypted-fallback.patch | reject session cookies when decryption fails (CVE-2026-39324) Rack::Session::Cookie configured with secrets: tried each encryptor and, on failure, decoded the cookie with the unencrypted coder. A cookie that is only Base64(Marshal) was accepted without the secret. When an encryptor is configured, leave the session empty instead. |
Samuel Williams <samuel.williams@oriontransfer.co.nz> | not-needed | debian upstream | upstream, https://github.com/rack/rack-session/commit/f43638cb3a4d15c3ecaf59e67a04b47fda08eeac | 2026-09-28 |
All known versions for source package 'ruby-rack-session'
- 2.1.2-2 (forky, sid)
- 2.1.1-0.1+deb13u1 (trixie-security)
- 2.1.1-0.1 (trixie)
