Image reports › ocimend.io/ruby
ocimend.io/ruby — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/ruby · Debian GNU/Linux 13 (trixie)
Latest: ocimend.io/ruby:latest-fips · checked 2026-09-27
Not FIPS-ready
No. ruby:latest-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade A: 379 known vulnerabilities
379 known vulnerabilities in 110 packages (2 critical, 14 high); none has a fix available yet.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Critical, high and exploited vulnerabilities in latest-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | CVE-2023-5841 | libopenexr-3-1-30 3.1.13-2 | no fix yet | Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 |
| critical | CVE-2023-5841 | libopenexr-dev 3.1.13-2 | no fix yet | Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 |
| high | CVE-2021-3575 | libopenjp2-7 2.5.3-2.1~deb13u2 | no fix yet | A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg. |
| high | CVE-2021-3575 | libopenjp2-7-dev 2.5.3-2.1~deb13u2 | no fix yet | A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg. |
| high | CVE-2024-25062 | libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | no fix yet | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. |
| high | CVE-2024-25062 | libxml2-dev 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | no fix yet | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. |
| high | CVE-2024-26461 | krb5-multidev 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libgssapi-krb5-2 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libgssrpc4t64 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libk5crypto3 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkadm5clnt-mit12 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkadm5srv-mit12 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkdb5-10t64 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5-3 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5-dev 1.21.3-5+deb13u1 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest-fips | Not FIPS-ready | A 379 2 critical | 2026-09-27 | ReportFix |