Fedora Account System
Red Hat Associate
Red Hat Customer
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:50728 https://access.redhat.com/errata/RHSA-2026:50728
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:50773 https://access.redhat.com/errata/RHSA-2026:50773
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:50778 https://access.redhat.com/errata/RHSA-2026:50778
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:50828 https://access.redhat.com/errata/RHSA-2026:50828
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:50827 https://access.redhat.com/errata/RHSA-2026:50827
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:54391 https://access.redhat.com/errata/RHSA-2026:54391
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:54393 https://access.redhat.com/errata/RHSA-2026:54393
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:54416 https://access.redhat.com/errata/RHSA-2026:54416