yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-41946
Component Overview
Vulnerability Overview
Name
CVE-2024-41946
Source
NVD (
link
)
Debian (
link
)
Description
REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull parser API. The REXML gem 3.3.3 or later include the patch to fix the vulnerability.
CWEs
CWE-400
CWE-400
Published Date
Aug 1, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/ruby/rexml/commit/033d1909a8f259d5a7c53681bcaf14f13bcf0368
Patch
https://github.com/ruby/rexml/security/advisories/GHSA-5866-49gr-22v4
Vendor Advisory
https://www.ruby-lang.org/en/news/2008/08/23/dos-vulnerability-in-rexml
Not Applicable
https://www.ruby-lang.org/en/news/2024/08/01/dos-rexml-cve-2024-41946
Vendor Advisory
Analysis
#
Affected Component
Analysis
ruby
Patched
Vulnerability Ratings
#
5.3
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ruby
buildroot
2025.02.x
3.4.9
Not Affected
ruby
buildroot
master
4.0.3
Not Affected
ruby
openwrt
master
4.0.2-r1
Not Affected
ruby
openwrt
openwrt-25.12
3.4.9-r1
Not Affected
ruby
yocto
master
4.0.5
Not Affected
ruby
yocto
scarthgap
3.3.10
Not Affected
Resolved with patches
#
ruby (yocto:kirkstone)
#
Title
Author
Resolve
1
Add support for XML entity expansion limitation in SAX and
NAITOH Jun <naitoh@gmail.com>
CVE-2024-41946