Описание
Security update for tree-sitter-ruby
This update for tree-sitter-ruby fixes the following issues
- CVE-2025-5889: brace-expansion: inefficient regular expression complexity in function expand of file index.js (bsc#1244345).
- CVE-2025-59343: tar-fs: tar-fs symlink validation bypass (bsc#1250517).
Changes for tree-sitter-ruby:
-
Use correct tree-sitter dirname instead of tree_sitter (bsc#1267461).
-
update to 0.23.1:
- ci(publish): add attestations and generate parser
- build: update bindings
- fix: remove unnecessary empty string usage
- chore: regenerate
- ci: update workflows
- fix(swift): include scanner.c
- update to 0.23.0:
- fix(go): correct test
- fix: handle != operator definition
- feat: support element references with blocks
- fix: do not require newline after block comment =end
- fix: parsing of multiple unicode escapes
- fix: correct repo url
- update to 0.21.0:
- feat: rewrite scanner with array header and regenerate
- build: update bindings and manifests
- fix: reverse precedence queries
- fix: escape braces in regex
- docs: update badges
- switch to download_files service
- add neovim links
- add license file to package
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1244345
- SUSE Bug 1250517
- SUSE Bug 1267461
- SUSE CVE CVE-2025-5889 page
- SUSE CVE CVE-2025-59343 page
Описание
A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.
Затронутые продукты
Ссылки
- CVE-2025-5889
- SUSE Bug 1244340
Описание
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
Затронутые продукты
Ссылки
- CVE-2025-59343
- SUSE Bug 1250515