Bug 2364966 (CVE-2025-46727)
Summary: | CVE-2025-46727 rubygem-rack: Unbounded-Parameter DoS in Rack::QueryParser | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | akostadi, amasferr, anthomas, cbartlet, dmayorov, ehelms, ggainey, jcantril, jlledo, juwatts, mhulan, mkudlej, mmakovy, nmoumoul, osousa, pcreech, periklis, rchan, rojacob, smallamp, tjochec |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | --- | |
Doc Text: |
A flaw was found in Rack::QueryParser. This vulnerability allows denial of service via oversized HTTP requests containing many parameters, resulting in memory exhaustion that consumes all available memory or CPU resource pinning, which keeps the CPU constantly busy.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2364996, 2364997, 2364998, 2364999, 2365000 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2025-05-08 00:01:08 UTC
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2025:7604 https://access.redhat.com/errata/RHSA-2025:7604 This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2025:7605 https://access.redhat.com/errata/RHSA-2025:7605 |