Project

General

Profile

Actions

Bug #21632

closed

Backport REXML CVE-2025-58767 fix

Bug #21632: Backport REXML CVE-2025-58767 fix

Added by Bo98 (Bo Anderson) 22 days ago. Updated 14 days ago.

Status:
Closed
Assignee:
-
Target version:
-
[ruby-core:<unknown>]

Description

Even though it's a bundled gem and not a default gem, it would be worthwhile backporting the fix for CVE-2025-58767 (https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/).

Ruby 3.4 PR: https://github.com/ruby/ruby/pull/14795
Ruby 3.3 PR: https://github.com/ruby/ruby/pull/14796

I'm not sure what to do for Ruby 3.2. It's a security fix so it qualifies for a backport, but there's other changes included in a version bump. Do we need a rexml 3.3.9.1?

Updated by Anonymous 21 days ago Actions #1

  • Status changed from Open to Closed

Applied in changeset git|a841c313c50e7ebf74df6e940334c34c68145270.


Update rexml to 3.4.4 for Ruby 3.4 (CVE-2025-58767) (#14795)

Update rexml to 3.4.4

[Backport #21632]

Updated by naitoh (Jun NAITOH) 17 days ago Actions #2

  • Status changed from Closed to Feedback
  • Backport changed from 3.2: UNKNOWN, 3.3: UNKNOWN, 3.4: UNKNOWN to 3.2: REQUIRED, 3.3: DONE, 3.4: DONE

I'm not sure what to do for Ruby 3.2. It's a security fix so it qualifies for a backport, but there's other changes included in a version bump.

I am a maintainer of REXML.
Ruby 3.2 is subject to security fixes, so I believe an update is necessary.

I created this PR.

https://github.com/ruby/ruby/pull/14823

Updated by naitoh (Jun NAITOH) 14 days ago Actions #3

  • Status changed from Feedback to Closed
  • Backport changed from 3.2: REQUIRED, 3.3: DONE, 3.4: DONE to 3.2: DONE, 3.3: DONE, 3.4: DONE

Merged.

Actions

Also available in: PDF Atom