Cryptopsyby CloudTrace

Image reports › ruby

ruby — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/ruby · Debian GNU/Linux 13 (trixie)

Latest: ruby:latest · checked 2026-09-25

Not FIPS-ready

No. ruby:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 451 known vulnerabilities

451 known vulnerabilities in 111 packages (2 critical, 21 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
criticalCVE-2023-5841libopenexr-3-1-30 3.1.13-2no fix yetDue to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2
criticalCVE-2023-5841libopenexr-dev 3.1.13-2no fix yetDue to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2
highCVE-2021-3575libopenjp2-7 2.5.3-2.1~deb13u2no fix yetA heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
highCVE-2021-3575libopenjp2-7-dev 2.5.3-2.1~deb13u2no fix yetA heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
highCVE-2019-19449linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry is not validated).
highCVE-2019-19814linux-libc-dev 6.12.107-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
highCVE-2021-3847linux-libc-dev 6.12.107-1no fix yetAn unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.
highCVE-2024-21803linux-libc-dev 6.12.107-1no fix yetUse After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C.
highCVE-2024-26461krb5-multidev 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libgssapi-krb5-2 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libgssrpc4t64 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libk5crypto3 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkadm5clnt-mit12 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkadm5srv-mit12 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkdb5-10t64 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyD 451 2 critical2026-09-25Full report