Back Linuxsecurity Fedora 43: rubygem-rack Moderate Denial Service Update 2025
Rack provides a minimal, modular and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers, web frameworks, and software in between (the so-called middleware) into a single method call. Update Information : Update to Rack 3.1.19
Rack provides a minimal, modular and adaptable interface for developing
web applications in Ruby. By wrapping HTTP requests and responses in
the simplest way possible, it unifies and distills the API for web
servers, web frameworks, and software in between (the so-called
middleware) into a single method call.
Update to Rack 3.1.19
* Tue Nov 4 2025 Vt Ondruch - 1:3.1.19-1 - Update to Rack 3.1.19
* Tue Nov 4 2025 Vt Ondruch - 1:3.1.19-1 - Update to Rack 3.1.19
[ 1 ] Bug #2402174 - CVE-2025-61770 rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) [ 2 ] Bug #2402175 - CVE-2025-61771 rack: Rack's multipart parser buffers large non\u2011file fields entirely in memory, enabling DoS (memory exhaustion) [ 3 ] Bug #2402200 - CVE-2025-61772 rack: Rack memory exhaustion denial of service [ 4 ] Bug #2403126 - CVE-2025-61780 rubygem-rack: Improper handling of headers in `Rack::Sendfile` may allow proxy bypass [ 5 ] Bug #2403180 - CVE-2025-61919 rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion
[ 1 ] Bug #2402174 - CVE-2025-61770 rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) [ 2 ] Bug #2402175 - CVE-2025-61771 rack: Rack's multipart parser buffers large non\u2011file fields entirely in memory, enabling DoS (memory exhaustion) [ 3 ] Bug #2402200 - CVE-2025-61772 rack: Rack memory exhaustion denial of service [ 4 ] Bug #2403126 - CVE-2025-61780 rubygem-rack: Improper handling of headers in `Rack::Sendfile` may allow proxy bypass [ 5 ] Bug #2403180 - CVE-2025-61919 rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b6e0f437b6' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
