Sinatra Vulnerability — Ubuntu Security Update (USN-8624-1)
This is a security release for Ubuntu 20.04, Ubuntu 22.04. The fix ships in the current release line (referenced builds: 22.04, 20.04, 18.04, 16.04). Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
सुधार कमांड
Debian/Ubuntu
sudo apt update && sudo apt upgrade
SharedLicense लाइसेंस के तहत इसका अर्थ
Your SharedLicense license itself is not affected — this is a change in Ubuntu 20.04, Ubuntu 22.04 software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.
-
USN-8624-1
Publication date
29 July 2026
Overview
Sinatra could be made to crash if it received specially crafted network
traffic.
Releases
Open side navigation
Packages
- ruby-sinatra – Ruby web-development dressed in a DSL
Details
It was discovered that Sinatra did not properly handle header parsing,
causing ETag generation to hang when given specific input. A remote
attacker could possibly use this issue to cause a denial of service.
It was discovered that Sinatra did not properly handle header parsing,
causing ETag generation to hang when given specific input. A remote
attacker could possibly use this issue to cause a denial of service.
Update instructions
After a standard system update you need to restart any applications that
use ruby-sinatra to make all the necessary changes.
Learn more about how to get the fixes.
The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
|
22.04
LTS jammy |
ruby-sinatra –
2.0.8.1-2+deb11u1ubuntu0.1~esm1 Ubuntu Pro |
||
|
20.04
LTS focal |
ruby-sinatra –
2.0.8.1-1ubuntu0.1~esm3 Ubuntu Pro |
||
|
18.04
LTS bionic |
ruby-sinatra –
1.4.8-1ubuntu0.1~esm3 Ubuntu Pro |
||
|
16.04
LTS xenial |
ruby-sinatra –
1.4.7-3ubuntu0.1~esm3 |
||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
References
संदर्भ
अपने सिस्टम में भेद्यताओं की जाँच करें
अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।
अपना सिस्टम जाँचें