CVE-2018-16396: Canonical Ubuntu Linux
High severity, CVSS 8.1. EPSS: 8% chance of exploitation in the next 30 days.
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 7.4 only; version 7.5 only; version 7.6 only
- Ruby-Lang Ruby: from 2.3.0, up to and including 2.3.7; from 2.4.0, up to and including 2.4.4; from 2.5.0, up to and including 2.5.1; version 2.6.0 only
Published 2018-11-16. Last modified 2026-06-17.