Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Fedora 43: Critical Ruby 3.4.7 Fixes for URI Exposure and REXML DoS

fedora
Calendar Grey November 9, 2025
Dist Fedora Esm H88
Upgrade Ruby to fix URI credential leakage and REXML denial of service vulnerabilities in Fedora 43.
Upgrade to Ruby 3.4.7

Summary

Ruby is the interpreted scripting language for quick and easy

object-oriented programming. It has many features to process text

files and to do system management tasks (as in Perl). It is simple,

straight-forward, and extensible.

Update Information:

Upgrade to Ruby 3.4.7. Fix URI Credential Leakage Bypass previous fixes. Resolves: CVE-2025-61594 Fix REXML denial of service. Resolves: CVE-2025-58767

Change Log

* Thu Oct 30 2025 Jun Aruga - 3.4.7-28 - Upgrade to Ruby 3.4.7. - Fix URI Credential Leakage Bypass previous fixes. Resolves: CVE-2025-61594 - Fix REXML denial of service. Resolves: CVE-2025-58767

References


[ 1 ] Bug #2396186 - CVE-2025-58767 rexml: REXML denial of service https://bugzilla.redhat.com/show_bug.cgi?id=2396186

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-28a9cec027' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ruby
Product: Fedora 43
Version: 3.4.7
Release: 28.fc43
Summary: An interpreter of object-oriented scripting language

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here