Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 40: ruby 2025-9bef972bb9 critical: DoS and memory exhaustion

fedora
Calendar Grey April 23, 2025
Dist Fedora Esm H88
Enhance Ruby to address Denial of Service vulnerabilities and user information disclosure problems in Fedora 40.
Upgrade to Ruby 3.3.8

Summary

Ruby is the interpreted scripting language for quick and easy

object-oriented programming. It has many features to process text

files and to do system management tasks (as in Perl). It is simple,

straight-forward, and extensible.

Update Information:

Upgrade to Ruby 3.3.8. CVE-2025-25186: Fix Net::IMAP vulnerable to possible DoS by memory exhaustion Resolves: rhbz#2345556 CVE-2025-27219: Denial of Service in CGI::Cookie.parse Resolves: rhbz#2357516 CVE-2025-27221: userinfo leakage in URI#join, URI#merge and URI#+

Change Log

* Thu Apr 10 2025 Vít Ondruch - 3.3.8-19 - Upgrade to Ruby 3.3.8. - CVE-2025-25186: Fix Net::IMAP vulnerable to possible DoS by memory exhaustion Resolves: rhbz#2345556 - CVE-2025-27219: Denial of Service in CGI::Cookie.parse Resolves: rhbz#2357516 - CVE-2025-27221: userinfo leakage in URI#join, URI#merge and URI#+

References


[ 1 ] Bug #2344680 - CVE-2025-25186 net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion https://bugzilla.redhat.com/show_bug.cgi?id=2344680 [ 2 ] Bug #2349699 - CVE-2025-27219 CGI: Denial of Service in CGI::Cookie.parse https://bugzilla.redhat.com/show_bug.cgi?id=2349699 [ 3 ] Bug #2349700 - CVE-2025-27221 uri: userinfo leakage in URI#join, URI#merge and URI#+ https://bugzilla.redhat.com/show_bug.cgi?id=2349700

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9bef972bb9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ruby
Product: Fedora 40
Version: 3.3.8
Release: 19.fc40
Summary: An interpreter of object-oriented scripting language

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here