FlawAtlas
Search the atlas
SUSE-SU-2025:03467-1 Not scored

Security update for rubygem-puma

This update for rubygem-puma fixes the following issues: Update to version 5.6.9. - CVE-2024-45614: improper header normalization allows for clients to clobber proxy set headers, which can lead to information leaks (bsc#1230848, fixed in an earlier update). - CVE-2024-21647: unbounded resource consumption due to invalid parsing of chunked encoding in HTTP/1.1 can lead to denial-of-service attacks (bsc#1218638, fixed in an earlier update) - CVE-2023-40175: incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers can lead to HTTP request smuggling attacks (bsc#1214425, fixed in an earlier update).

Exploit probability Not scored
Published October 7, 2025
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Availability Extension 15 SP6 rubygem-puma
SUSE:Linux Enterprise High Availability Extension 15 SP7 rubygem-puma
openSUSE:Leap 15.6 rubygem-puma

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:03467-1

This update for rubygem-puma fixes the following issues: Update to version 5.6.9. - CVE-2024-45614: improper header normalization allows for clients to clobber proxy set headers, which can lead to information leaks (bsc#1230848, fixed in an earlier update). - CVE-2024-21647: unbounded resource consumption due to invalid parsing of chunked encoding in HTTP/1.1 can lead to denial-of-service attacks (bsc#1218638, fixed in an earlier update) - CVE-2023-40175: incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers can lead to HTTP request smuggling attacks (bsc#1214425, fixed in an earlier update).

View original source

05 / REFERENCES

Further evidence