Security update for ruby2.5
This update for ruby2.5 fixes the following issues: - CVE-2024-49761: ReDoS vulnerability in REXML gem (bsc#1232440 bsc#1232441). - CVE-2025-58767: denial of service when parsing XML containing multiple XML declarations (bsc#1250016). - CVE-2026-27820: insufficient checks in `zstream_buffer_ungets` can lead to a buffer overflow (bsc#1259239).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ruby2.5 fixes the following issues: - CVE-2024-49761: ReDoS vulnerability in REXML gem (bsc#1232440 bsc#1232441). - CVE-2025-58767: denial of service when parsing XML containing multiple XML declarations (bsc#1250016). - CVE-2026-27820: insufficient checks in `zstream_buffer_ungets` can lead to a buffer overflow (bsc#1259239).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1232440
- https://bugzilla.suse.com/1232441
- https://bugzilla.suse.com/1250016
- https://bugzilla.suse.com/1259239
- https://www.suse.com/security/cve/CVE-2024-49761
- https://www.suse.com/security/cve/CVE-2025-58767
- https://www.suse.com/security/cve/CVE-2026-27820
- https://www.suse.com/support/update/announcement/2026/suse-su-20261066-1/