FlawAtlas
Search the atlas
SUSE-SU-2026:1066-1 Not scored

Security update for ruby2.5

This update for ruby2.5 fixes the following issues: - CVE-2024-49761: ReDoS vulnerability in REXML gem (bsc#1232440 bsc#1232441). - CVE-2025-58767: denial of service when parsing XML containing multiple XML declarations (bsc#1250016). - CVE-2026-27820: insufficient checks in `zstream_buffer_ungets` can lead to a buffer overflow (bsc#1259239).

Exploit probability Not scored
Published March 26, 2026
Required by Not available
Last source change March 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7 ruby2.5

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1066-1

This update for ruby2.5 fixes the following issues: - CVE-2024-49761: ReDoS vulnerability in REXML gem (bsc#1232440 bsc#1232441). - CVE-2025-58767: denial of service when parsing XML containing multiple XML declarations (bsc#1250016). - CVE-2026-27820: insufficient checks in `zstream_buffer_ungets` can lead to a buffer overflow (bsc#1259239).

View original source

05 / REFERENCES

Further evidence