stable

ruby-3.3.8-19.fc40

FEDORA-2025-9bef972bb9 created by vondruch a year ago for Fedora 40

Upgrade to Ruby 3.3.8.

  • CVE-2025-25186: Fix Net::IMAP vulnerable to possible DoS by memory exhaustion
    Resolves: #2345556
  • CVE-2025-27219: Denial of Service in CGI::Cookie.parse
    Resolves: #2357516
  • CVE-2025-27221: userinfo leakage in URI#join, URI#merge and URI#+

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-9bef972bb9

This update has been submitted for testing by vondruch.

a year ago

This update's test gating status has been changed to 'ignored'.

a year ago

vondruch edited this update.

a year ago

vondruch edited this update.

a year ago

This update has been pushed to testing.

a year ago

This update has been submitted for stable by bodhi.

a year ago

This update has been pushed to stable.

a year ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
modified
a year ago
approved
a year ago
BZ#2344680 CVE-2025-25186 net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion
0
0
BZ#2345556 CVE-2025-25186 ruby: Net::IMAP vulnerable to possible DoS by memory exhaustion [fedora-40]
0
0
BZ#2349699 CVE-2025-27219 CGI: Denial of Service in CGI::Cookie.parse
0
0
BZ#2349700 CVE-2025-27221 uri: userinfo leakage in URI#join, URI#merge and URI#+
0
0
BZ#2357516 CVE-2025-27219 ruby: Denial of Service in CGI::Cookie.parse [fedora-all]
0
0

Automated Test Results