🛡️ CVE-2026-54906 on Ubuntu — ruby-concurrent
Description
concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent::ResourceLimitError. This is a synchronization correctness issue in the public Concurrent::ReadWriteLock API. This vulnerability is fixed in 1.3.7.
Distribution advisory
This page covers CVE-2026-54906 as tracked by Ubuntu, for the package ruby-concurrent. No fixed version has been recorded for this distribution yet.
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.
Affected software
UBUNTU-CVE-2026-54906 is recorded against 1 package.
- ruby-concurrent
Timeline and source
Published on 24 June 2026 and last revised on 29 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| ruby-concurrent | — | — |
References
Similar Threats
- Unknown DEBIAN-CVE-2026-54904
- Unknown DEBIAN-CVE-2026-54905
- Unknown DEBIAN-CVE-2026-54906
- Unknown UBUNTU-CVE-2026-54904
- Unknown UBUNTU-CVE-2026-54905
More UBUNTU CVE 2026 advisories
Browse all of UBUNTU CVE 2026 in the advisory index.
- UBUNTU-CVE-2026-54898
- UBUNTU-CVE-2026-54899
- UBUNTU-CVE-2026-54900
- UBUNTU-CVE-2026-54901
- UBUNTU-CVE-2026-54902
- UBUNTU-CVE-2026-54903
- UBUNTU-CVE-2026-54904
- UBUNTU-CVE-2026-54905
- UBUNTU-CVE-2026-54908
- UBUNTU-CVE-2026-54909
- UBUNTU-CVE-2026-54911
- UBUNTU-CVE-2026-54919
- UBUNTU-CVE-2026-55063
- UBUNTU-CVE-2026-55153
- UBUNTU-CVE-2026-55191
- UBUNTU-CVE-2026-55192
Free Vulnerability Check
Is your site affected by UBUNTU-CVE-2026-54906?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against UBUNTU-CVE-2026-54906 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.