CVE-2019-8324: Debian Linux

High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Rubygems Rubygems: from 2.6.0, up to and including 3.0.2

Published 2019-06-17. Last modified 2026-06-17.