Security update for ruby2.5
This update for ruby2.5 fixes the following issues: - CVE-2024-35221: Fixed remote DoS via YAML manifest (bsc#1225905) - CVE-2024-47220: Fixed HTTP request smuggling in WEBrick (bsc#1230930) - CVE-2024-49761: Fixed ReDOS vulnerability by updating REXML to 3.3.9 (bsc#1232440) - CVE-2025-24294: Fixed denial of service (DoS) caused by an insufficient check on the length of a decompressed domain name within a DNS packet in resolv gem (bsc#1246430) - CVE-2025-27219: Fixed denial of service in CGI::Cookie.parse (bsc#1237804) - CVE-2025-27220: Fixed ReDoS in CGI::Util#escapeElement (bsc#1237806) - CVE-2025-27221: Fixed userinfo leakage in URI#join, URI#merge and URI#+ (bsc#1237805) - CVE-2025-6442: Fixed ruby WEBrick read_header HTTP request smuggling vulnerability (bsc#1245254)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ruby2.5 fixes the following issues: - CVE-2024-35221: Fixed remote DoS via YAML manifest (bsc#1225905) - CVE-2024-47220: Fixed HTTP request smuggling in WEBrick (bsc#1230930) - CVE-2024-49761: Fixed ReDOS vulnerability by updating REXML to 3.3.9 (bsc#1232440) - CVE-2025-24294: Fixed denial of service (DoS) caused by an insufficient check on the length of a decompressed domain name within a DNS packet in resolv gem (bsc#1246430) - CVE-2025-27219: Fixed denial of service in CGI::Cookie.parse (bsc#1237804) - CVE-2025-27220: Fixed ReDoS in CGI::Util#escapeElement (bsc#1237806) - CVE-2025-27221: Fixed userinfo leakage in URI#join, URI#merge and URI#+ (bsc#1237805) - CVE-2025-6442: Fixed ruby WEBrick read_header HTTP request smuggling vulnerability (bsc#1245254)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1225905
- https://bugzilla.suse.com/1230930
- https://bugzilla.suse.com/1232440
- https://bugzilla.suse.com/1235773
- https://bugzilla.suse.com/1237804
- https://bugzilla.suse.com/1237805
- https://bugzilla.suse.com/1237806
- https://bugzilla.suse.com/1245254
- https://bugzilla.suse.com/1246430
- https://www.suse.com/security/cve/CVE-2024-35221
- https://www.suse.com/security/cve/CVE-2024-47220
- https://www.suse.com/security/cve/CVE-2024-49761
- https://www.suse.com/security/cve/CVE-2025-24294
- https://www.suse.com/security/cve/CVE-2025-27219
- https://www.suse.com/security/cve/CVE-2025-27220
- https://www.suse.com/security/cve/CVE-2025-27221
- https://www.suse.com/security/cve/CVE-2025-6442
- https://www.suse.com/support/update/announcement/2025/suse-su-20254264-1/