[WID-SEC-2025-1472] Ruby: Schwachstelle ermöglicht Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.9 (mittel) Remoteangriff ja Datum 07.07.2025 Stand UPDATE 20.05.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Ruby ist eine interpretierte, objektorientierte Skriptsprache. Produkte UPDATE 04.01.2026 RESF Rocky Linux UPDATE 11.12.2025 Red Hat Enterprise Linux Oracle Linux UPDATE 26.10.2025 SUSE Linux UPDATE 03.09.2025 Ubuntu Linux UPDATE 04.08.2025 Amazon Linux 2 UPDATE 23.07.2025 Open Source Ruby <3.2.9 07.07.2025 Open Source Ruby resolv <=0.2.2 Open Source Ruby resolv = 0.3.0 Open Source Ruby resolv <=0.6.1 Angriff Angriff Ein Angreifer kann eine Schwachstelle in Ruby ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A vulnerability in Ruby's `resolv` library allows a remote attacker to cause a denial of service, with a CVSS base score of 7.5. Affected versions include Ruby versions prior to 3.2.9, and `resolv` library versions <=0.2.2, =0.3.0, and <=0.6.1. Major Linux distributions have released updates; administrators should apply the relevant vendor patches.