Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Rocky Linux 9 RLSA-2024:10860 critical: ruby REXML ReDoS

rocky
Calendar Grey December 19, 2024
Rockylinux Esm H88
Rocky Linux maintainers have released crucial updates for Ruby packages to mitigate a severe ReDoS vulnerability.
Important: ruby:3.1 security update

Summary

An update is available for rubygem-mysql2, rubygem-pg, module.rubygem-pg, module.rubygem-mysql2. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list


RPMs

rubygem-mysql2-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.aarch64.rpm

rubygem-mysql2-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.ppc64le.rpm

rubygem-mysql2-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.s390x.rpm

rubygem-mysql2-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.src.rpm

rubygem-mysql2-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.x86_64.rpm

rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.aarch64.rpm

rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.ppc64le.rpm

rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.s390x.rpm

rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.x86_64.rpm

rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.aarch64.rpm

rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.ppc64le.rpm

rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.s390x.rpm

rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.4.0+20785+5faae8e3.x86_64.rpm

Read the Full Advisory

References

No references

CVES

https://www.cve.org/CVERecord?id=CVE-2024-49761

Severity
important

Name: RLSA-2024:10860
Affected Products: Rocky Linux 9

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=2322153


Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here