CVE-2011-2686

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

mediumEPSS 2.6%

Description

Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900. NOTE: this issue exists because of a regression during Ruby 1.8.6 development.

Metrics

Severity
medium
no public PoC known
84.3 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
2.6 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-04-17 23:15 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux9.0

  • linux

    ubuntu / ruby2.3xenial

  • macos

    apple / macos

  • other

    fedoraproject / fedora36

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    ruby-min2.6.0

  • bitnami

    ruby-min2.7.0

  • bitnami

    ruby-min3.0.0

  • bitnami

    ruby-min3.1.0

  • bitnami

    ruby-min3.2.0

  • bitnami

    ruby-min3.3.0

  • bitnami

    ruby-min

  • maven

    org.jruby:jruby0.8.3

  • maven

    org.jruby:jruby0.9.1

  • maven

    org.jruby:jruby0.9.2

  • maven

    org.jruby:jruby0.9.8

  • maven

    org.jruby:jruby0.9.9

  • maven

    org.jruby:jruby1.0

  • maven

    org.jruby:jruby1.0.1

  • maven

    org.jruby:jruby1.0.2

  • maven

    org.jruby:jruby1.0.3

  • maven

    org.jruby:jruby1.0RC1

  • maven

    org.jruby:jruby1.0RC2

  • maven

    org.jruby:jruby1.0RC3

  • maven

    org.jruby:jruby1.1

  • maven

    org.jruby:jruby1.1.1

  • maven

    org.jruby:jruby1.1.2

  • maven

    org.jruby:jruby1.1.3

  • maven

    org.jruby:jruby1.1.4

References & sources

Linked CVEs

Show 11 more CVEs
IDCVE-2011-2686