CVE-2025-24294: Possible Denial of Service in resolv gem
14-Jul-2025 18
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. This vulnerability has been assigned the CVE identifier CVE-2025-24294. We recommend upgrading the resolv gem.
Details
The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet.
An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.
This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.
CVE-2025-24294: Possible Denial of Service in resolv gem #ruby #rubydeveloper #rubyonrails #CVE-2025-24294: #Possible #Denial #Service #resolv #gem #service https://rubyonrails.ba/link/cve-2025-24294-possible-denial-of-service-in-resolv-gem