Bug 2491522 (CVE-2026-47242)

Summary: CVE-2026-47242 net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akostadi, amasferr, dmayorov, eshamard, jlledo, jvasik, kaycoth, pantinor, rblanco, rhel-process-autobot, tsedmik, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Net::IMAP, a Ruby library that implements Internet Message Access Protocol (IMAP) client functionality. This vulnerability arises from improper input validation when handling ID field values and arguments to the `enable` command. A remote attacker could exploit this by injecting specially crafted input, leading to the execution of arbitrary IMAP commands. This could allow an attacker to manipulate IMAP sessions or access sensitive information.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2524416    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-22 21:02:08 UTC
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

Comment 2 errata-xmlrpc 2026-08-05 09:40:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:50728 https://access.redhat.com/errata/RHSA-2026:50728

Comment 3 errata-xmlrpc 2026-08-05 11:21:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:50773 https://access.redhat.com/errata/RHSA-2026:50773

Comment 4 errata-xmlrpc 2026-08-05 12:04:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:50778 https://access.redhat.com/errata/RHSA-2026:50778

Comment 5 errata-xmlrpc 2026-08-05 16:37:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:50828 https://access.redhat.com/errata/RHSA-2026:50828

Comment 6 errata-xmlrpc 2026-08-05 16:40:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:50827 https://access.redhat.com/errata/RHSA-2026:50827

Comment 7 errata-xmlrpc 2026-08-12 14:48:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:54391 https://access.redhat.com/errata/RHSA-2026:54391

Comment 8 errata-xmlrpc 2026-08-12 15:02:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:54393 https://access.redhat.com/errata/RHSA-2026:54393

Comment 9 errata-xmlrpc 2026-08-12 18:25:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:54416 https://access.redhat.com/errata/RHSA-2026:54416