Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3858-1 | ruby2.7 security update |
Debian DSA |
DSA-5677-1 | ruby3.1 security update |
EUVD |
EUVD-2024-1008 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2. |
Github GHSA |
GHSA-v5h6-c2hv-hv3r | StringIO buffer overread vulnerability |
Ubuntu USN |
USN-6853-1 | Ruby vulnerability |
Ubuntu USN |
USN-7734-1 | Ruby vulnerabilities |
Tue, 04 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 May 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 13 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ruby-lang
Ruby-lang ruby |
|
| CPEs | cpe:2.3:a:ruby-lang:ruby:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Ruby-lang
Ruby-lang ruby |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T17:17:47.556Z
Reserved: 2024-02-22T00:00:00.000Z
Link: CVE-2024-27280
Updated: 2025-11-03T18:08:20.761Z
Status : Deferred
Published: 2024-05-14T15:11:56.940
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-27280
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN