CVE-2024-27280
published 2024-05-14CVE-2024-27280: A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.36%
81.9th percentile
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| debian | ruby2.7 | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
| debian | ruby3.1 | < ruby2.7 2.7.4-1+deb11u2 (bullseye) | ruby2.7 2.7.4-1+deb11u2 (bullseye) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_oracle5.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-27280: macOS Sequoia 15.7
vendor_apple·2025-09-15·CVSS 9.8
CVE-2024-27280 [CRITICAL] CVE-2024-27280: macOS Sequoia 15.7
Apple Security Update: About the security content of macOS Sequoia 15.7
Product: macOS Sequoia
Version: 15.7
CVE: CVE-2024-27280
Component: CVE-2024-27280
Apple
CVE-2024-27280: macOS Sonoma 14.8
vendor_apple·2025-09-15·CVSS 9.8
CVE-2024-27280 [CRITICAL] CVE-2024-27280: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2024-27280
Component: CVE-2024-27280
Apple
CVE-2024-27280: macOS Tahoe 26
vendor_apple·2025-09-15·CVSS 9.8
CVE-2024-27280 [CRITICAL] CVE-2024-27280: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2024-27280
Component: CVE-2024-27280
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2025-09-03·CVSS 9.8
CVE-2024-27282 [CRITICAL] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby incorrectly handled certain IO stream
methods. A remote attacker could use this issue to cause Ruby to crash,
resulting in a denial of service, or possibly obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-27280)
It was discovered that the Ruby regex compiler incorrectly handled
certain memory operations. A remote attacker could possibly use this
issue to obtain sensitive memory contents. This issue only affected
Ubuntu 18.04 LTS. (CVE-2024-27282)
It was discovered that Ruby incorrectly handled parsing of certain XML
characters through the REXML gem. An attacker could use this issue to
cause Ruby to crash, resulting in a denial of service. This i
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Ruby) — CVE-2024-27280
vendor_oracle·2025-01-15·CVSS 5.3
CVE-2024-27280 [CRITICAL] Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Ruby) — CVE-2024-27280
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Ruby) vulnerability
CVE: CVE-2024-27280
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Ubuntu
Ruby vulnerability
vendor_ubuntu·2024-06-26
CVE-2024-27280 Ruby vulnerability
Title: Ruby vulnerability
Summary: Ruby could be made to crash or expose sensitive information login if it
processed certain strings.
It was discovered that Ruby incorrectly handled the ungetbyte and ungetc
methods. A remote attacker could use this issue to cause Ruby to crash,
resulting in a denial of service, or possibly obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ruby: Buffer overread vulnerability in StringIO
vendor_redhat·2024-03-21·CVSS 9.8
CVE-2024-27280 [CRITICAL] CWE-126 ruby: Buffer overread vulnerability in StringIO
ruby: Buffer overread vulnerability in StringIO
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.
A buffer overread flaw was found in rubygem StringIO. The ungetbyte and ungetc methods on a StringIO object can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value.
Mitigation: Mitigation for this issue is either not available or the currently available options don't
Debian
CVE-2024-27280: ruby2.7 - A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby...
vendor_debian·2024·CVSS 9.8
CVE-2024-27280 [CRITICAL] CVE-2024-27280: ruby2.7 - A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby...
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.
Scope: local
bullseye: resolved (fixed in 2.7.4-1+deb11u2)
OSV
ruby2.5, ruby2.7, ruby3.0, ruby3.2, ruby3.3 vulnerabilities
osv·2025-09-03·CVSS 9.8
CVE-2024-27280 [CRITICAL] ruby2.5, ruby2.7, ruby3.0, ruby3.2, ruby3.3 vulnerabilities
ruby2.5, ruby2.7, ruby3.0, ruby3.2, ruby3.3 vulnerabilities
It was discovered that Ruby incorrectly handled certain IO stream
methods. A remote attacker could use this issue to cause Ruby to crash,
resulting in a denial of service, or possibly obtain sensitive
information. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-27280)
It was discovered that the Ruby regex compiler incorrectly handled
certain memory operations. A remote attacker could possibly use this
issue to obtain sensitive memory contents. This issue only affected
Ubuntu 18.04 LTS. (CVE-2024-27282)
It was discovered that Ruby incorrectly handled parsing of certain XML
characters through the REXML gem. An attacker could use this issue to
cause Ruby to crash, resulting in a denial of service. This issue only
affected Ubu
OSV
CVE-2024-27280: A buffer-overread issue was discovered in StringIO 3
osv·2024-05-14·CVSS 9.8
CVE-2024-27280 [CRITICAL] CVE-2024-27280: A buffer-overread issue was discovered in StringIO 3
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.
OSV
StringIO buffer overread vulnerability
osv·2024-03-25
CVE-2024-27280 [CRITICAL] StringIO buffer overread vulnerability
StringIO buffer overread vulnerability
An issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.
The `ungetbyte` and `ungetc` methods on a StringIO can read past the end of a string, and a subsequent call to `StringIO.gets` may return the memory value.
This vulnerability is not affected StringIO 3.0.3 and later, and Ruby 3.2.x and later.
We recommend to update the StringIO gem to version 3.0.3 or later. In order to ensure compatibility with bundled version in older Ruby series, you may update as follows instead:
* For Ruby 3.0 users: Update to `stringio` 3.0.1.1
* For Ruby 3.1 users: Update to `stringio` 3.1.0.2
You can use `gem update stringio` to update it. If you are using bundler, please add `gem "stringio", ">= 3.0.1.2"` to yo
GHSA
StringIO buffer overread vulnerability
ghsa·2024-03-25
CVE-2024-27280 [CRITICAL] CWE-120 StringIO buffer overread vulnerability
StringIO buffer overread vulnerability
An issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4.
The `ungetbyte` and `ungetc` methods on a StringIO can read past the end of a string, and a subsequent call to `StringIO.gets` may return the memory value.
This vulnerability is not affected StringIO 3.0.3 and later, and Ruby 3.2.x and later.
We recommend to update the StringIO gem to version 3.0.3 or later. In order to ensure compatibility with bundled version in older Ruby series, you may update as follows instead:
* For Ruby 3.0 users: Update to `stringio` 3.0.1.1
* For Ruby 3.1 users: Update to `stringio` 3.1.0.2
You can use `gem update stringio` to update it. If you are using bundler, please add `gem "stringio", ">= 3.0.1.2"` to yo
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://hackerone.com/reports/1399856https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/http://seclists.org/fulldisclosure/2025/Sep/53http://seclists.org/fulldisclosure/2025/Sep/54http://seclists.org/fulldisclosure/2025/Sep/55https://hackerone.com/reports/1399856https://lists.debian.org/debian-lts-announce/2024/09/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/27LUWREIFTP3MQAW7QE4PJM4DPAQJWXF/https://lists.fedoraproject.org/archives/list/[email protected]/message/XYDHPHEZI7OQXTQKTDZHGZNPIJH7ZV5N/https://security.netapp.com/advisory/ntap-20250502-0003/https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/
2024-05-14
Published