Bug 7255 - [Anolis OS 23] Bugfix for CVE-2023-22795
Summary: [Anolis OS 23] Bugfix for CVE-2023-22795
Status: NEW
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P3-Medium S3-normal
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-11-14 15:24 UTC by 小龙
Modified: 2023-11-14 15:24 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-11-14 15:24:51 UTC
Description:
ActionDispatch<6.1.7.1和<7.0.4.1中存在与If-None-Match标头相关的基于正则表达式的DoS漏洞。当Ruby版本低于3.2.0时,特制的HTTPIf-None-Match标头可能会导致正则表达式引擎进入灾难性回溯状态。这可能会导致进程使用大量CPU和内存,从而导致可能的DoS漏洞。运行受影响版本的所有用户都应立即升级或使用其中一种解决方法。

Broken commit info:

Bugfix commit info:
https://github.com/rails/rails/commit/484fc9185db6c6a6a49ab458b11f9366da02bab2 (6-1-stable)
https://bugzilla.suse.com/attachment.cgi?id=864346
https://bugzilla.suse.com/attachment.cgi?id=864345