已关闭
[bundle]合并修复CVE-2026-47240 CVE-2026-47241 CVE-2026-47242 #127
tong_1001创建于  23 天前关闭于  13 天前
tong_1001
23 天前 创建

一、漏洞信息

漏洞编号:

漏洞归属组件:

漏洞归属的版本:

CVSS V3.0分值:

漏洞简述:

漏洞公开时间:

漏洞创建时间:

漏洞详情参考链接:

漏洞分析指导链接:
https://gitee.com/openeuler/cve-manager/blob/master/doc/md/manual.md

二、漏洞分析结构反馈

影响性分析说明:

openEuler评分:

受影响版本排查(受影响/不受影响):

二、缺陷分析结构反馈
影响性分析说明:

缺陷严重等级:(Critical/High/Moderate/Low)

缺陷根因说明:

受影响版本排查(受影响/不受影响):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2

修复是否涉及abi变化(是/否):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2

likedislike
Ttong_1001
23 天前 issue类型由 CVE和安全问题 改变为 缺陷
openeuler-ci-botopeneuler-ci-bot成员
23 天前 将 hubin1305 设为负责人
openeuler-ci-botopeneuler-ci-bot成员
23 天前 修改了issue 的描述
openeuler-ci-bot
openeuler-ci-bot成员
23 天前 评论:

以下的要求不是强制性的, 未按模板评论时对issue无任何影响
issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, 缺陷严重等级, 受影响版本排查(受影响/不受影响), 修复是否涉及abi变化(是/否))不能省略,省略后defect-manager将无法正常解析填写内容.
评论区可能使用到的指令说明:

指令 指令说明 使用权限
/check-issue 触发defect-manager校验 不限
/reason xxx /reason +挂起或取消条件 不限

影响性分析说明:

缺陷严重等级:(Critical/High/Moderate/Low)

缺陷根因说明:

受影响版本排查(受影响/不受影响):

  1. openEuler-20.03-LTS-SP4:
  2. openEuler-22.03-LTS-SP3:
  3. openEuler-22.03-LTS-SP4:
  4. openEuler-24.03-LTS:
  5. openEuler-24.03-LTS-SP1:
  6. openEuler-24.03-LTS-SP2:

abi变化(是/否):

  1. openEuler-20.03-LTS-SP4:
  2. openEuler-22.03-LTS-SP3:
  3. openEuler-22.03-LTS-SP4:
  4. openEuler-24.03-LTS:
  5. openEuler-24.03-LTS-SP1:
  6. openEuler-24.03-LTS-SP2:

缺陷issue处理具体操作请参考:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/defect-manager-manual.md
pr关联issue具体操作请参考:
https://docs.atomgit.com/docs/help/home/org_project/pullrequests/pr-related-issue

likedislike
openeuler-ci-botopeneuler-ci-bot成员
23 天前 添加了label:DEFECT/UNFIXED
Ttong_1001
23 天前 issue类型由 缺陷 改变为 任务
tong_1001
20 天前 评论:

/branches openEuler-24.03-LTS-SP4

likedislike
xiaoo_robot
xiaoo_robot
20 天前 评论:

正在自动化处理任务,任务编号:TASK-gitcode__ruby-127-20260817094334,指定分支:openEuler-24.03-LTS-SP4

✅ 任务结束 (用时: 146分钟)

likedislike
tong_1001
20 天前 评论:

/assign

likedislike
openeuler-ci-botopeneuler-ci-bot成员
20 天前 将 tong_1001 设为负责人,移除负责人 hubin1305
xiaoo_robotxiaoo_robot
20 天前 关联了pull request:fix: bundle CVE-2026-47240+CVE-2026-47241+CVE-2026-47242 - openEuler-24.03-LTS-SP4
xiaoo_robot
xiaoo_robot
20 天前 评论:

─── CVE-2026-47240 ───
是否需要修复:是
是否存在适配:否
上游社区补丁:https://github.com/ruby/net-imap/commit/7228b22b81a49198172fb111a343fef80236bbf5.patch

分支修复情况:
1.openEuler-24.03-LTS-SP4: 已修复

PR:- openEuler-24.03-LTS-SP4: https://gitcode.com/src-openeuler/ruby/merge_requests/315
适配情况:无

─── CVE-2026-47241 ───
是否需要修复:是
是否存在适配:否
上游社区补丁:https://github.com/ruby/net-imap/commit/892da94f5c6034028a3aabf27d5981bd41be249c.patch

分支修复情况:
1.openEuler-24.03-LTS-SP4: 已修复

PR:- openEuler-24.03-LTS-SP4: https://gitcode.com/src-openeuler/ruby/merge_requests/315
适配情况:无

─── CVE-2026-47242 ───
是否需要修复:是
是否存在适配:否
上游社区补丁:https://github.com/ruby/net-imap/commit/f173c6e900f8a2c43431c55cbe09b5233131ffe5.patch

分支修复情况:
1.openEuler-24.03-LTS-SP4: 已修复

PR:- openEuler-24.03-LTS-SP4: https://gitcode.com/src-openeuler/ruby/merge_requests/315
适配情况:无

likedislike
xiaoo_robot
xiaoo_robot
20 天前 评论:

补丁适配报告 (CVE-2026-47242)

1. backport-CVE-2026-47242-1.patch

  • 状态: 适配成功 (status=adapted)
  • 置信度: high
  • 冲突说明: File renamed/moved: lib/net/imap/command_data.rb -> .bundle/gems/net-imap-0.3.4/lib/net/imap/command_data.rb, adapted changes accordingly; Skipped 1 non-critical test file (test/net/imap/test_command_data.rb) - does not exist in baseline (bundled gem ships without test/ directory). Hunk content unchanged - pure path relocation with context verified identical to baseline. git apply --check passed, git diff --stat confirmed baseline changed (1 file, 17 insertions, 15 deletions).

2. backport-CVE-2026-47242-2.patch

  • 状态: 适配成功 (status=adapted)
  • 置信度: high
  • 冲突说明: File renamed/moved: lib/net/imap/command_data.rb -> .bundle/gems/net-imap-0.3.4/lib/net/imap/command_data.rb, adapted changes accordingly; Skipped 1 non-critical file(s): test/net/imap/test_command_data.rb does not exist in baseline

3. backport-CVE-2026-47240.patch

  • 状态: 适配成功 (status=adapted)
  • 置信度: high
  • 冲突说明: 跨版本适配(net-imap 0.6+ → 0.3.4)。文件路径映射:lib/net/imap/command_data.rb → .bundle/gems/net-imap-0.3.4/lib/net/imap/command_data.rb。Hunk 1(send_literal 修改)上下文匹配,原样保留。Hunk 2(新增 non_sync_literal_allowed? 和 capable_literal_minus? 方法)上下文不匹配(0.6+ 有 '# NOTE: +num+' 注释和 put_string(Integer(num).to_s),0.3.4 无),且引用的 capabilities_cached?/capable? 方法在 0.3.4 不存在,内联为 @responses["CAPABILITY"]&.last 直接访问(遵循 imap.rb:901 的现有模式)。Hunks 3&4(test_imap.rb 测试)丢弃:net-imap 0.3.4 gem 无 test/ 目录,测试基础设施(with_fake_server/with_extensions/greeting_capabilities/ignore_abrupt_eof)不存在。安全修复核心逻辑(拒绝无服务器支持的非同步 literal + 关闭连接 + 抛出 DataFormatError)完整保留。

4. backport-CVE-2026-47241.patch

  • 状态: 适配成功 (status=adapted)
  • 置信度: high
  • 冲突说明: Hunk1 (lib/net/imap/command_data.rb): 路径重命名为 .bundle/gems/net-imap-0.3.4/lib/net/imap/command_data.rb(net-imap 在 Ruby 3.2.2 为 bundled gem 0.3.4);正则 /~?{[1-9]\d*+?}\z/n 改为 /{\d++?}\z/n,上下文与 baseline 完全匹配(仅 2 行行号偏移)。Hunk2 (test/net/imap/test_command_data.rb): 跳过——测试文件在全源码树均不存在(gem 不附带 test 套件),属非关键文件;该 hunk 仅向已存在的测试方法追加 7 行,无法凭此重建整个测试文件。adapted_patch 已应用到 source_dir(commit 677c7bb),git diff --stat HEAD~1 确认 1 文件 1 增 1 删;worktree 在应用前状态(HEAD~1) git apply --check exit=0 干净应用。
likedislike
tong_1001
19 天前 评论:
likedislike
tong_1001
19 天前 评论:

补丁信息如下:

补丁序号 补丁链接 补丁描述 备注
1 https://github.com/ruby/net-imap/commit/2922a38fdaea440009c14642e00e39c5eec48582 🍒 pick e224fd6 (#684): 🥅 Validate that Atom and Flag are not empty
2 https://github.com/ruby/net-imap/commit/705f0dedddfa87f88f15a45ad8143d9c2a90497a 🍒 pick 5c213ab (#675): 🏷️ Allow 64-bit Integer arguments
3 https://github.com/ruby/net-imap/commit/e8de4cb2c486177519718d05328466740af612b6 🍒 pick 3fe06a4 (#676): 🥅 Ensure send_number_data input is an Integer
4 https://github.com/ruby/net-imap/commit/1262f6cebb5578212d656c48de99057de31c7248 🍒 pick 94c7957 (#677): 📚⚠️ Boost visibility of raw data argument warnings 仅修改注释
5 https://github.com/ruby/net-imap/commit/cc9d9dc07c3ff2ce13ab59a27bb72d4a4c45a1d2 🍒 pick 0d508fa (#681): 🥅 Validate server's literal byte size format
6 https://github.com/ruby/net-imap/commit/47d29f2d087140ac3296963c20bbfc444c68d82d 🍒 pick b02182c (#678): ✅🐛 Fix FakeServer CommandParseError (tests only) 仅修改测试用例
7 https://github.com/ruby/net-imap/commit/0b50e7e59cf1f1ea66638270e1a8b5883247c3cf 🍒 pick ef6fde3 (#678): ✅ Handle "stream closed" as EOF (tests only) 仅修改测试用例
8 https://github.com/ruby/net-imap/commit/506466bf6cd2c1b59d6655f1f12d30677670f685 🍒 pick a27a002 (#678): ✅ Allow test server td ignore abrupt EOF 仅修改测试用例
9 https://github.com/ruby/net-imap/commit/0e26b7e4de85201d8a14ee1f6751609d1ebf2c28 🍒 pick 95afda8 (#679): ♻️ Allow RawData.new to directly set parts array
10 https://github.com/ruby/net-imap/commit/172d2e8abf13e852b65e5159453e0c68dfe358fc 🍒 pick 257e51d (#679): ♻️ Extract RawData.split(string)
11 https://github.com/ruby/net-imap/commit/473dc44c93d75ffe9fd0e26ef6152eba565cf797 🍒 pick 17b6463 (#493): 🧵 Join the receiver after closing the socket
12 https://github.com/ruby/net-imap/commit/05c07d151458ff044a0f2eca3ab23fd04b3ea847 🍒 pick 5bddf68 (#493): 📖 Document that #disconnect joins receiver thread 仅修改注释
13 https://github.com/ruby/net-imap/commit/5577098085eca9caface6e9d729bcbdbfb471433 🍒 pick 9becbf1 (#493): 🧵 Don't lock around socket close in #disconnect
14 https://github.com/ruby/net-imap/commit/d47394036253fa4fdf23e561c124f486e5b6be85 🍒 pick 0c919fb (#493): ♻️ Simplify shutdown of socket in #disconnect
15 https://github.com/ruby/net-imap/commit/9390b632bde8d1f5fa8263c2fb05edaef5eeed7a 🍒 pick aab64f9 (#686): 🧵 Fix deadlock in #disconnect
16 https://github.com/ruby/net-imap/commit/f173c6e900f8a2c43431c55cbe09b5233131ffe5 🍒 pick e3c50fa (#698): ♻️ Refactor RawText, add improve test coverage
17 https://github.com/ruby/net-imap/commit/7449e180ad6d4211624b7e25138d0b17a86da0fc 🍒 pick 8d9397a (#698): 🥅 Validate QuotedString contains only valid bytes
18 https://github.com/ruby/net-imap/commit/3aca4bb36e1ee407f4c9ed77594d67aadc62839b 🍒 pick 1f97168 (#699): 🥅 Validate #enable arguments are all atoms
19 https://github.com/ruby/net-imap/commit/892da94f5c6034028a3aabf27d5981bd41be249c 🍒 pick d6ddd29 (#700): 🐛 Prevent trailing {0} in RawData validation
20 https://github.com/ruby/net-imap/commit/7228b22b81a49198172fb111a343fef80236bbf5 🍒 pick 62a0da6 (#701): 🥅 Validate non-synchronizing literals support
21 https://github.com/ruby/net-imap/commit/8faa2e123141d2cf9e2d8533fa5642902380c19a 🍒 pick ae9f83b (#701): ♻️ Extract str.bytesize lvar in send_literal
22 https://github.com/ruby/net-imap/commit/0373573b60dc4691293e46e8d799651b70b4aeca 🍒 pick 0ea9eba (#701): ✅ Fix flaky tests for MacOS, TruffleRuby 仅修改测试用例
23 https://github.com/ruby/net-imap/commit/65a424e4d1a14d312bcc53d1b3003ca44f4c6018 ✅ Avoid endless method defs for Ruby 2.7 compatibility 仅修改测试用例
24 https://github.com/ruby/net-imap/commit/341d94248bd375a14b04d27cea8fa3155dbc1249 🧵 Synchronize FakeServer::Connection#close to avoid double logout 仅修改测试用例
25 https://github.com/ruby/net-imap/commit/f672be4b41764967304ea54a0cccd230699d4568 Bump version to 0.4.25 版本发布,不回合
likedislike
Ttong_1001
17 天前 关联了pull request:fix CVE-2026-47240 CVE-2026-47241 CVE-2026-47242
此处折叠了6条事件消息 查看更多
openeuler-ci-botopeneuler-ci-bot成员
13 天前 关联了pull request:[sync] PR-327: fix CVE-2026-47240 CVE-2026-47241 CVE-2026-47242
tong_1001
13 天前 评论:

/close

likedislike
openeuler-ci-botopeneuler-ci-bot成员
13 天前 issue状态由 待办的 改变为 已完成
openeuler-ci-botopeneuler-ci-bot成员
13 天前 关闭了 issue