Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 2025:1369-1 crucial: resolution for ruby2.5 DoS and ReDoS issue

suse
Calendar Grey April 24, 2025
Dist Suse Esm H88
The latest revision of ruby2.5 tackles major vulnerabilities, notably denial of service alongside ReDoS. Safeguard your infrastructure accordingly.
* bsc#1230930 * bsc#1235773 * bsc#1237804 * bsc#1237806

Summary

## This update for ruby2.5 fixes the following issues: * CVE-2025-27219: Fixed denial of service in CGI::Cookie.parse (bsc#1237804) * CVE-2025-27220: Fixed ReDoS in CGI::Util#escapeElement (bsc#1237806) Other fixes: \- Improved fix for CVE-2024-47220 (bsc#1230930, bsc#1235773) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1369=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-1369=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4

References

* bsc#1230930

* bsc#1235773

* bsc#1237804

* bsc#1237806

Cross-

* CVE-2024-47220

* CVE-2025-27219

* CVE-2025-27220

CVSS scores:

* CVE-2024-47220 ( SUSE ): 8.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2024-47220 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

* CVE-2024-47220 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2025-27219 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-27219 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-27219 ( NVD ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

* CVE-2025-27219 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-27220 ( SUSE ): 6.9

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:1369-1
Release Date: 2025-04-24T17:12:13Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here