Fedora Account System
Red Hat Associate
Red Hat Customer
Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions that allows attackers to cause out-of-bounds memory writes. Attackers can exploit this by crafting multi-gigabyte XML files to trigger buffer overflows resulting in information disclosure, data modification, or denial of service.
* Why CVSS 7.0 (not 8.6) * libxml2 requires a crafted multi-gigabyte XML file (>2 GB), which normal RH upload and request limits block in practice. AC:H reflects that barrier; C:L/I:L stay because out-of-bounds writes are still possible if those limits are bypassed. 7.0 is a modest drop from 8.6 without treating it as DoS-only.
.