[CLSA-2026:1776952176] ruby: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-23 13:49:41 UTC
Description:
- CVE-2024-39908: fix ReDoS in REXML parser for repeated `>` / character reference payloads - CVE-2024-41123: fix ReDoS in REXML source.match when no terminator string is specified - CVE-2024-41946: add XML entity expansion limit to REXML SAX and pull parsers - CVE-2024-43398: fix DoS via deep elements with namespace-conflicted attributes in REXML tree parser
Updated packages:
  • ruby-3.0.7-165.el9_5.tuxcare.els4.i686.rpm
    sha:096850ce58d7c7d74cde9325d37abdfd7b42112f3528722f08d22291e5c091eb
  • ruby-3.0.7-165.el9_5.tuxcare.els4.x86_64.rpm
    sha:b0c2068119ba07b09194e87e0ae4b230320104612315dff4da4ab3ac63eae628
  • ruby-default-gems-3.0.7-165.el9_5.tuxcare.els4.noarch.rpm
    sha:4be18445699ef7266d8c19cd0a1d60953b59c4b54ab785e0e9ee55c70a861b47
  • ruby-devel-3.0.7-165.el9_5.tuxcare.els4.i686.rpm
    sha:98228a7acc7f71a9e6dc950035dbe4c88853831f79e7b4ebe4809a54e33bbd57
  • ruby-devel-3.0.7-165.el9_5.tuxcare.els4.x86_64.rpm
    sha:85b05e2115f38300178676281baf8be1bc9eca83a479d2848d6f46731cfeea45
  • ruby-doc-3.0.7-165.el9_5.tuxcare.els4.noarch.rpm
    sha:38ab8f1a7d44511514ffc033cb04fb58c0af2b408db702527353909c97011ea8
  • ruby-libs-3.0.7-165.el9_5.tuxcare.els4.i686.rpm
    sha:14f840bb7d2fa52339ef44c1a940add3489cb4a321bf8cf1ca2d3a7aede954ef
  • ruby-libs-3.0.7-165.el9_5.tuxcare.els4.x86_64.rpm
    sha:6f77639cc2699a84307302a07aa074866c2ad93493daaa57f8c587f6c0d11755
  • rubygem-bigdecimal-3.0.0-165.el9_5.tuxcare.els4.x86_64.rpm
    sha:d43a8be1e3343a95e4c3ccf6a6d6fb5275423618c75b62fb3535700e988f2619
  • rubygem-bundler-2.2.33-165.el9_5.tuxcare.els4.noarch.rpm
    sha:9104b9d1fe6217bbd515a40c5584d935ed7f079dedd2109b74a69235022c0d81
  • rubygem-io-console-0.5.7-165.el9_5.tuxcare.els4.x86_64.rpm
    sha:0a61cefdbd4eb3dd2fd74a2d17f9cc80f5b4d9f92fd7e52d2faf1f7baacddbe4
  • rubygem-irb-1.3.5-165.el9_5.tuxcare.els4.noarch.rpm
    sha:ba6496201a8be97f59f904ba9069b7ddf3c830b362949eb6248e58510cd069d3
  • rubygem-json-2.5.1-165.el9_5.tuxcare.els4.x86_64.rpm
    sha:f3578d7dae8b49bd264a3ebb3081de468cc5e4be4a928408720cd6ca1b15f0c3
  • rubygem-minitest-5.14.2-165.el9_5.tuxcare.els4.noarch.rpm
    sha:b682d7aa9c3e54b368541379c7ab28a73b115945a24f2eed3e5ce33ba47e61db
  • rubygem-power_assert-1.2.1-165.el9_5.tuxcare.els4.noarch.rpm
    sha:8d7663ead94ceb8bb02fbd17a09a9abc69dae66384bd8a224622e4167c725c51
  • rubygem-psych-3.3.2-165.el9_5.tuxcare.els4.x86_64.rpm
    sha:67feafbed4a3adf714ce488450f24e9548b8a8eaa17f5b6063c095cf27396af6
  • rubygem-rake-13.0.3-165.el9_5.tuxcare.els4.noarch.rpm
    sha:3aa1a0ab1b98a6b340c4c0624dbcf14bda98207947990e6e965fc3e2249b02de
  • rubygem-rbs-1.4.0-165.el9_5.tuxcare.els4.noarch.rpm
    sha:3bbb57c7b8611694677f7915f6ad79548bcd2e52a067edde7761e332653c04f4
  • rubygem-rdoc-6.3.4.1-165.el9_5.tuxcare.els4.noarch.rpm
    sha:643dbcb6a2ab1205f0a1af1bc8db2cb4b3b84721995964fcb031d74d3cc5821a
  • rubygem-rexml-3.2.5-165.el9_5.tuxcare.els4.noarch.rpm
    sha:cad241f41eb8226dedf5fdab89f10e4395ad3c82be431c702396b1b16180130b
  • rubygem-rss-0.2.9-165.el9_5.tuxcare.els4.noarch.rpm
    sha:3137a1ac15b0bcb8c033f27434a805b3ec30ee0fbb6ce94546be4d28cb542e4a
  • rubygem-test-unit-3.3.7-165.el9_5.tuxcare.els4.noarch.rpm
    sha:90541eda95da7c806088a62ca70bd5fb1c07b9e88f28fea7febd79453326e517
  • rubygem-typeprof-0.15.2-165.el9_5.tuxcare.els4.noarch.rpm
    sha:ba0759532d37de5ab0760416f0833c9708328220adc2834fd8b33910b7f00537
  • rubygems-3.2.33-165.el9_5.tuxcare.els4.noarch.rpm
    sha:e8b732f4cb3d01ab5a50d48de725f57611ab718d362055fd60e78fd8d611a6a3
  • rubygems-devel-3.2.33-165.el9_5.tuxcare.els4.noarch.rpm
    sha:a99a850aa900f90a507bb44b21ab5a2f993cf95e591cc527da055172e7b643e1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.