File tree Expand file tree Collapse file tree 1 file changed +39
-0
lines changed Expand file tree Collapse file tree 1 file changed +39
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ gem : nokogiri
3+ ghsa : vvfq-8hwr-qm4m
4+ url : https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-vvfq-8hwr-qm4m
5+ title : Nokogiri updates packaged libxml2 to 2.13.6 to resolve
6+ CVE-2025-24928 and CVE-2024-56171
7+ date : 2025-02-18
8+ description : |
9+ ## Summary
10+
11+ Nokogiri v1.18.3 upgrades its dependency libxml2 to
12+ [v2.13.6](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.13.6).
13+
14+ libxml2 v2.13.6 addresses:
15+
16+ - CVE-2025-24928
17+ - described at https://gitlab.gnome.org/GNOME/libxml2/-/issues/847
18+ - CVE-2024-56171
19+ - described at https://gitlab.gnome.org/GNOME/libxml2/-/issues/828
20+
21+ ## Impact
22+
23+ ### CVE-2025-24928
24+
25+ Stack-buffer overflow is possible when reporting DTD validation
26+ errors if the input contains a long (~3kb) QName prefix.
27+
28+ ### CVE-2024-56171
29+
30+ Use-after-free is possible during validation against untrusted
31+ XML Schemas (.xsd) and, potentially, validation of untrusted documents
32+ against trusted Schemas if they make use of `xsd:keyref` in combination
33+ with recursively defined types that have additional identity constraints.
34+ patched_versions :
35+ - " >= 1.18.3"
36+ related :
37+ url :
38+ - https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-vvfq-8hwr-qm4m
39+ - https://github.com/advisories/GHSA-vvfq-8hwr-qm4m
You can’t perform that action at this time.
0 commit comments