Several security issues were fixed in Nokogiri.. ========================================================================== Ubuntu Security Notice USN-7659-1 July 21, 2025 ruby-nokogiri vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Nokogiri. Software Description: - ruby-nokogiri: HTML, XML, SAX, and Reader parser for Ruby Details: It was discovered Nokogiri did not correctly parse XML Schemas. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-26247) Agustin Gianni discovered that Nokogiri did not correctly parse XML and HTML files. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or leak sensitive information. (CVE-2022-29181) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS ruby-nokogiri 1.13.1+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS ruby-nokogiri 1.10.7+dfsg1-2ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7659-1 CVE-2020-26247, CVE-2022-29181, CVE-2022-40303 . Numerous vulnerabilities within Nokogiri may result in unauthorized code execution and service disruption. It's advisable to update for enhanced security.. Ubuntu Nokogiri Security, Ruby Nokogiri Update, Ubuntu 20.04 Security Patch, Code Execution vulnerabilities, Denial of Service Risk. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.