Bug 2491522 (CVE-2026-47242)
| Summary: | CVE-2026-47242 net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akostadi, amasferr, dmayorov, eshamard, jlledo, jvasik, kaycoth, pantinor, rblanco, rhel-process-autobot, tsedmik, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Net::IMAP, a Ruby library that implements Internet Message Access Protocol (IMAP) client functionality. This vulnerability arises from improper input validation when handling ID field values and arguments to the `enable` command. A remote attacker could exploit this by injecting specially crafted input, leading to the execution of arbitrary IMAP commands. This could allow an attacker to manipulate IMAP sessions or access sensitive information.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2524416 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-06-22 21:02:08 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:50728 https://access.redhat.com/errata/RHSA-2026:50728 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:50773 https://access.redhat.com/errata/RHSA-2026:50773 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:50778 https://access.redhat.com/errata/RHSA-2026:50778 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:50828 https://access.redhat.com/errata/RHSA-2026:50828 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:50827 https://access.redhat.com/errata/RHSA-2026:50827 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:54391 https://access.redhat.com/errata/RHSA-2026:54391 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:54393 https://access.redhat.com/errata/RHSA-2026:54393 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:54416 https://access.redhat.com/errata/RHSA-2026:54416 |