Intel

AIKIDO-2026-10900

ruby is vulnerable to Use-After-Free

Use-After-FreeCVE-2026-46727 Published 6 days ago

75

High Risk

This Affects:

OSruby
4.0.0 - 4.0.4
Fixed in 4.0.5
Are you affected? Scan for Free

TL;DR

Ruby contains a use-after-free vulnerability in the pthread-based getaddrinfo timeout handler used by Addrinfo.getaddrinfo(..., timeout:) and Socket.tcp(..., resolv_timeout:). A remote attacker able to delay DNS responses near the configured timeout may trigger a race condition causing the Ruby process to crash.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

ruby is vulnerable to Use-After-Free in versions 4.0.0 - 4.0.4.

How to fix this

Upgrade the ruby library to the patch version.