Advisories ยป MGASA-2025-0290

Updated ruby packages fix security vulnerabilities

Publication date: 13 Nov 2025
Modification date: 13 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-25186 , CVE-2025-27219 , CVE-2025-27220 , CVE-2025-27221

Description

Net::IMAP vulnerable to possible DoS by memory exhaustion.
(CVE-2025-25186)
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in
the CGI library contains a potential Denial of Service (DoS)
vulnerability. The method does not impose any limit on the length of the
raw cookie value it processes. This oversight can lead to excessive
resource consumption when parsing extremely large cookies.
(CVE-2025-27219)
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of
Service (ReDoS) vulnerability exists in the Util#escapeElement method.
(CVE-2025-27220)
In the URI gem before 1.0.3 for Ruby, the URI handling methods
(URI.join, URI#merge, URI#+) have an inadvertent leakage of
authentication credentials because userinfo is retained even after
changing the host. (CVE-2025-27221)
                

References

SRPMS

9/core