CVE-2020-10933: Debian Linux

Medium severity, CVSS 5.3. EPSS: 2.5% chance of exploitation in the next 30 days.

An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 31 only
  • Ruby-Lang Ruby: from 2.5.0, up to and including 2.5.7; from 2.6.0, up to and including 2.6.5; version 2.7.0 only

Published 2020-05-04. Last modified 2026-06-17.