[Apollo] Advisories Statistics light light Login

RLSA-2025:4488

Security Mirrored from RHSA-2025:4488
Issued at: 2025-07-29
Updated at: 2025-07-29

Synopsis

Moderate: ruby:3.1 security update



Description

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

Security Fix(es):

* rexml: DoS vulnerability in REXML (CVE-2024-39908)

* rexml: rubygem-rexml: DoS when parsing an XML having many specific characters such as whitespace character, >] and ]> (CVE-2024-41123)

* rexml: DoS vulnerability in REXML (CVE-2024-41946)

* rexml: DoS vulnerability in REXML (CVE-2024-43398)

* CGI: ReDoS in CGI::Util#escapeElement (CVE-2025-27220)

* CGI: Denial of Service in CGI::Cookie.parse (CVE-2025-27219)

* uri: userinfo leakage in URI#join, URI#merge and URI#+ (CVE-2025-27221)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2298243 2302268 2302272 2307297 2349696 2349699 2349700

CVEs

CVE-2024-39908 CVE-2024-41123 CVE-2024-41946 CVE-2024-43398 CVE-2025-27219 CVE-2025-27220 CVE-2025-27221

Affected packages

Rocky Linux 9 aarch64 - AppStream

ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.src.rpm ruby-bundled-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm ruby-bundled-gems-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm ruby-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm ruby-debugsource-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm ruby-default-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-devel-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm ruby-doc-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-bigdecimal-0:3.1.1-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-bigdecimal-debuginfo-0:3.1.1-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-bundler-0:2.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-io-console-0:0.5.11-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-io-console-debuginfo-0:0.5.11-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-irb-0:1.4.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-json-0:2.6.1-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-json-debuginfo-0:2.6.1-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-minitest-0:5.15.0-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-mysql2-doc-0:0.5.4-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-pg-debuginfo-0:1.3.5-1.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-pg-debugsource-0:1.3.5-1.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-pg-doc-0:1.3.5-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-power_assert-0:2.0.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-psych-0:4.0.4-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-psych-debuginfo-0:4.0.4-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-rake-0:13.0.6-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rbs-0:2.7.0-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-rbs-debuginfo-0:2.7.0-146.module+el9.5.0+31847+8b291b93.aarch64.rpm rubygem-rdoc-0:6.4.1.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rexml-0:3.3.9-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rss-0:0.3.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-devel-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-test-unit-0:3.5.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-typeprof-0:0.21.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-libs-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm ruby-libs-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.aarch64.rpm

Rocky Linux 9 ppc64le - AppStream

ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.src.rpm ruby-bundled-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm ruby-bundled-gems-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm ruby-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm ruby-debugsource-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm ruby-default-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-devel-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm ruby-doc-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-bigdecimal-0:3.1.1-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-bigdecimal-debuginfo-0:3.1.1-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-bundler-0:2.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-io-console-0:0.5.11-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-io-console-debuginfo-0:0.5.11-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-irb-0:1.4.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-json-0:2.6.1-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-json-debuginfo-0:2.6.1-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-minitest-0:5.15.0-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-mysql2-doc-0:0.5.4-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-pg-debuginfo-0:1.3.5-1.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-pg-debugsource-0:1.3.5-1.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-pg-doc-0:1.3.5-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-power_assert-0:2.0.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-psych-0:4.0.4-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-psych-debuginfo-0:4.0.4-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-rake-0:13.0.6-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rbs-0:2.7.0-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-rbs-debuginfo-0:2.7.0-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm rubygem-rdoc-0:6.4.1.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rexml-0:3.3.9-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rss-0:0.3.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-devel-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-test-unit-0:3.5.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-typeprof-0:0.21.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-libs-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm ruby-libs-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.ppc64le.rpm

Rocky Linux 9 s390x - AppStream

ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.src.rpm ruby-bundled-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm ruby-bundled-gems-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm ruby-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm ruby-debugsource-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm ruby-default-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-devel-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm ruby-doc-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-bigdecimal-0:3.1.1-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-bigdecimal-debuginfo-0:3.1.1-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-bundler-0:2.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-io-console-0:0.5.11-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-io-console-debuginfo-0:0.5.11-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-irb-0:1.4.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-json-0:2.6.1-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-json-debuginfo-0:2.6.1-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-minitest-0:5.15.0-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-mysql2-doc-0:0.5.4-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-pg-debuginfo-0:1.3.5-1.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-pg-debugsource-0:1.3.5-1.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-pg-doc-0:1.3.5-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-power_assert-0:2.0.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-psych-0:4.0.4-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-psych-debuginfo-0:4.0.4-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-rake-0:13.0.6-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rbs-0:2.7.0-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-rbs-debuginfo-0:2.7.0-146.module+el9.5.0+31847+8b291b93.s390x.rpm rubygem-rdoc-0:6.4.1.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rexml-0:3.3.9-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rss-0:0.3.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-devel-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-test-unit-0:3.5.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-typeprof-0:0.21.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-libs-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm ruby-libs-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.s390x.rpm

Rocky Linux 9 x86_64 - AppStream

ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.src.rpm ruby-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm ruby-bundled-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm ruby-bundled-gems-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm ruby-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm ruby-debugsource-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm ruby-default-gems-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-devel-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm ruby-doc-0:3.1.7-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-bigdecimal-0:3.1.1-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-bigdecimal-debuginfo-0:3.1.1-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-bundler-0:2.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-io-console-0:0.5.11-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-io-console-debuginfo-0:0.5.11-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-irb-0:1.4.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-json-0:2.6.1-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-json-debuginfo-0:2.6.1-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-minitest-0:5.15.0-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-mysql2-0:0.5.4-1.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-mysql2-debuginfo-0:0.5.4-1.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-mysql2-debugsource-0:0.5.4-1.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-mysql2-doc-0:0.5.4-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.src.rpm rubygem-pg-0:1.3.5-1.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-pg-debuginfo-0:1.3.5-1.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-pg-debugsource-0:1.3.5-1.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-pg-doc-0:1.3.5-1.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-power_assert-0:2.0.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-psych-0:4.0.4-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-psych-debuginfo-0:4.0.4-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-rake-0:13.0.6-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rbs-0:2.7.0-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-rbs-debuginfo-0:2.7.0-146.module+el9.5.0+31847+8b291b93.x86_64.rpm rubygem-rdoc-0:6.4.1.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rexml-0:3.3.9-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-rss-0:0.3.1-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygems-devel-0:3.3.27-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-test-unit-0:3.5.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm rubygem-typeprof-0:0.21.3-146.module+el9.5.0+31847+8b291b93.noarch.rpm ruby-libs-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm ruby-libs-debuginfo-0:3.1.7-146.module+el9.5.0+31847+8b291b93.x86_64.rpm