Fix REXML denial of service.

Upgrade to rexml gem 3.4.4.
https://www.ruby-lang.org/en/news/2025/09/18/dos-rexml-cve-2025-58767/

Resolves: rhbz#2396204
Resolves: CVE-2025-58767
This commit is contained in:
Jun Aruga 2025-10-23 18:03:49 +01:00
commit 9b8531baa2
3 changed files with 22 additions and 1 deletions

View file

@ -135,7 +135,7 @@
%global rbs_version 3.8.0
%global repl_type_completor_version 0.1.9
%global resolv_replace_version 0.1.1
%global rexml_version 3.4.0
%global rexml_version 3.4.4
%global rinda_version 0.2.0
%global rss_version 0.3.1
%global syslog_version 0.2.0
@ -239,6 +239,8 @@ Source19: test_rubygems_con.rb
# default RDoc gem as shipped in Ruby tarball. This should not be needed for
# Ruby 3.5+.
Source20: https://github.com/ruby/rdoc/blob/master/lib/rubygems_plugin.rb
# rexml gem
Source21: https://rubygems.org/gems/rexml-%{rexml_version}.gem
# The load directive is supported since RPM 4.12, i.e. F21+. The build process
# fails on older Fedoras.
@ -775,6 +777,10 @@ analysis result in RBS format, a standard type description format for Ruby
# Provide an example of usage of the tapset:
cp -a %{SOURCE3} .
rm -rf .bundle/gems/rexml-3.4.0
rm .bundle/specifications/rexml-3.4.0.gemspec
rm gems/rexml-3.4.0.gem
%build
autoconf
@ -814,6 +820,16 @@ popd
%install
rm -rf %{buildroot}
cp -p %{SOURCE21} gems/
make -C %{_vpath_builddir} runruby \
TESTRUN_SCRIPT="%{_builddir}/%{buildsubdir}/bin/gem unpack %{SOURCE21} --target='%{_builddir}/%{buildsubdir}/.bundle/gems'"
make --silent -C %{_vpath_builddir} runruby \
TESTRUN_SCRIPT="%{_builddir}/%{buildsubdir}/bin/gem spec '%{SOURCE21}' --ruby" \
> .bundle/specifications/rexml-%{rexml_version}.gemspec
sed -i -e '/^rexml/ s/3.4.0/3.4.4/' gems/bundled_gems
%make_install -C %{_vpath_builddir}
# TODO: Regenerate RBS parser in lib/rbs/parser.rb
@ -1880,6 +1896,9 @@ make -C %{_vpath_builddir} runruby TESTRUN_SCRIPT=" \
- Upgrade to Ruby 3.4.7.
- Fix URI Credential Leakage Bypass previous fixes.
Resolves: CVE-2025-61594
- Fix REXML denial of service.
Resolves: rhbz#2396204
Resolves: CVE-2025-58767
* Mon Aug 18 2025 Jarek Prokop <jprokop@redhat.com> - 3.4.5-25
- Upgrade to Ruby 3.4.5.