Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20998-1

Опубликовано: 22 июн. 2026
Источник: suse-cvrf

Описание

Security update for tree-sitter-ruby

This update for tree-sitter-ruby fixes the following issues

  • CVE-2025-5889: brace-expansion: inefficient regular expression complexity in function expand of file index.js (bsc#1244345).
  • CVE-2025-59343: tar-fs: tar-fs symlink validation bypass (bsc#1250517).

Changes for tree-sitter-ruby:

  • Use correct tree-sitter dirname instead of tree_sitter (bsc#1267461).

  • update to 0.23.1:

  • ci(publish): add attestations and generate parser
  • build: update bindings
  • fix: remove unnecessary empty string usage
  • chore: regenerate
  • ci: update workflows
  • fix(swift): include scanner.c
  • update to 0.23.0:
  • fix(go): correct test
  • fix: handle != operator definition
  • feat: support element references with blocks
  • fix: do not require newline after block comment =end
  • fix: parsing of multiple unicode escapes
  • fix: correct repo url
  • update to 0.21.0:
  • feat: rewrite scanner with array header and regenerate
  • build: update bindings and manifests
  • fix: reverse precedence queries
  • fix: escape braces in regex
  • docs: update badges
  • switch to download_files service
  • add neovim links
  • add license file to package

Список пакетов

openSUSE Leap 16.0
tree-sitter-ruby-0.23.1-160000.3.1
tree-sitter-ruby-devel-0.23.1-160000.3.1

Описание

A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.


Затронутые продукты
openSUSE Leap 16.0:tree-sitter-ruby-0.23.1-160000.3.1
openSUSE Leap 16.0:tree-sitter-ruby-devel-0.23.1-160000.3.1

Ссылки

Описание

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.


Затронутые продукты
openSUSE Leap 16.0:tree-sitter-ruby-0.23.1-160000.3.1
openSUSE Leap 16.0:tree-sitter-ruby-devel-0.23.1-160000.3.1

Ссылки