#1143080 rails: CVE-2026-66066

Package:
src:rails
Source:
src:rails
Submitter:
Salvatore Bonaccorso
Date:
2026-08-02 00:53:02 UTC
Severity:
normal
Tags:
#1143080#5
Date:
2026-07-30 08:16:11 UTC
From:
To:
Hi,

The following vulnerability was published for rails.

CVE-2026-66066[0]:
| Possible arbitrary file read and remote code execution in Active
| Storage variant processing

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66066
https://www.cve.org/CVERecord?id=CVE-2026-66066
[1] https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143080#8
Date:
2026-08-02 00:37:40 UTC
From:
To:
Hello,

Bug #1143080 in rails reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/ruby-team/rails/-/commit/da71c5b619c1bdb7e8c6eb67f4bd884619a7bc64

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143080

#1143080#15
Date:
2026-08-02 00:50:43 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
rails, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143080@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Quigley <tsimonq2@debian.org> (supplier of updated rails package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 01 Aug 2026 19:35:55 -0500
Source: rails
Architecture: source
Version: 2:7.2.3.2+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Team <pkg-ruby-extras-maintainers@lists.alioth.debian.org>
Changed-By: Simon Quigley <tsimonq2@debian.org>
Closes: 1143080
Changes:
 rails (2:7.2.3.2+dfsg-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release (Closes: #1143080).
Checksums-Sha1:
 b0c534cb7ae585568677e6601bd1fb004127a669 4666 rails_7.2.3.2+dfsg-1.dsc
 06d31344ca5207f81b6da0d0218906096a1d6b8c 8080472 rails_7.2.3.2+dfsg.orig.tar.xz
 2fd6a68a1734b7e1d5e01da7b5d19b062490c41e 103264 rails_7.2.3.2+dfsg-1.debian.tar.xz
 85803f4c03e0c837d5def8492968a34dfa299d57 7310 rails_7.2.3.2+dfsg-1_source.buildinfo
Checksums-Sha256:
 9dcf04c066e3ad96e2b72ed067bbaaabb855512f7a207f2ad6861f1154ac7f59 4666 rails_7.2.3.2+dfsg-1.dsc
 80ac6ba4b140fb88c2a20d983ce565d1f8fd868b613dc407d08c0ec35581c1bc 8080472 rails_7.2.3.2+dfsg.orig.tar.xz
 b76a34f597c6b27b97896f6a7dc9c2a0fda35ac8ba25d5674a220f311661ced5 103264 rails_7.2.3.2+dfsg-1.debian.tar.xz
 71f24a28e1735b770b68a359d9e6f18b29f646367b2f57124066e09b66d3371e 7310 rails_7.2.3.2+dfsg-1_source.buildinfo
Files:
 29eaea3cf43fed5246744af19fe20831 4666 ruby optional rails_7.2.3.2+dfsg-1.dsc
 be62dc7b56d474e95dca8d20bca56c58 8080472 ruby optional rails_7.2.3.2+dfsg.orig.tar.xz
 4615e583aed26caca2a8cb30ac315050 103264 ruby optional rails_7.2.3.2+dfsg-1.debian.tar.xz
 947053e910927a6ffd9e6964f295062d 7310 ruby optional rails_7.2.3.2+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmpukUYACgkQ4n8s+EWM
L6Rh6g/9HtdUazz8i2Z2egWYQcZB1tVsib+D9VmRaeeCW2LofL/k+LDh47sOexkT
O3RsAiKzM9y/x+hEPXZFnoKMFnRnVg0BEzGm/fB6Rn4ssDRiguvF0WAAg4GH082F
TFfvm8BSHa6TH6Qj5eDEZ6z+GI97sZLgeFqHfXoX6zJs32F1uCN169voFZImUXj0
5xtyQtDmUnnLqN2BSiC9t9Goy39AYiC444U963Tokk5GtT6h1mKPtj8efsqMKiIf
UFaXUqH3DPTAuLgoS/i6RyH7pCgKSfAWLEUF2JoVyiGJaUAhBmYMMQ+XFUJz0K+q
ODmpuwCcP7tEdzmAFfC3x99jVbRPko5Qsy8jB1fs8ED0MfJomxBjN+XhPvoJXIw5
OShODisEAmrzahiaRnR9Vs2xjTwu5ds6FEJEjhoMhR2SNJ3Ae+g6xDW+CkxosJj9
hG8t71Ar2jgVZI99jHLojl2pKc27nFlZbisyAYmETmoiblEnSnf7WvzTPG+t6aMj
E3zHYaRqdPRSo5ugiFMaVRE4tOxHsWuGhY469jWRCb5iuiOHUbDKqVqna3x7XtrG
w6P+bNbvIHQCLNN19nBFwKwXXQscYlG3oIs88gpRdl7OdYY2JtaBf+PtElnVdKfN
VSFecylaeUanP6M1cmJi3i+mAj7LGg1vARaFrddudojXMDvhgYQ=
=50vo
-----END PGP SIGNATURE-----