CVE-2024-58378: Nokogiri before 1.16.2 Use-After-Free via xmlTextReader
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nokogirito a version that resolves this vulnerability.Fixed in 1.15.6 - Upgrade
Upgrade
nokogirito a version that resolves this vulnerability.Fixed in 1.16.2 - Compensating control
If using Nokogiri versions before 1.16.2, avoid the XML Reader interface with DTD validation and XInclude expansion enabled to prevent the xmlTextReader use-after-free (CVE-2024-25062) in the xmlTextReader module underlying Nokogiri::XML::Reader.