Ruby Tackles CVE-2024-27282
-
CVE-2024-27282: Arbitrary memory address read vulnerability with Regex search
We have released the Ruby version 3.0.7, 3.1.5, 3.2.4 and 3.3.1 that have a security fix for an arbitrary memory address read vulnerability in Regex search.
-
Ruby 3.3.1 Released
Ruby 3.3.1 has been released.
This release includes security fixes.
-
Ruby 3.2.4 Released
Ruby 3.2.4 has been released.
See the GitHub releases for further details.
-
Ruby 3.1.5 Released
Ruby 3.1.5 has been released.
See the GitHub releases for further details.
-
Ruby 3.0.7 Released
Ruby 3.0.7 has been released.
See the GitHub releases for further details.
After this release, Ruby 3.0 reaches EOL. In other words, this is expected to be the last release of Ruby 3.0 series. We will not release Ruby 3.0.8 even if a security vulnerability is found (but could release if a severe regression is found). We recommend all Ruby 3.0 users to start migration to Ruby 3.3, 3.2, or 3.1 immediately.