Resource exhaustion in net-imap - CVE-2025-43857

 

Resource exhaustion in net-imap - CVE-2025-43857

Published: May 2, 2025


Vulnerability identifier: #VU108125
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43857
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when reading server responses. A malicious server can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

net-imap
Astronomer with IBM
openEuler
Anolis OS
rubygem-rss
rubygem-io-console
rubygem-typeprof
rubygem-rbs
rubygem-did_you_mean
rubygem-racc
rubygem-irb
rubygem-power_assert
rubygem-openssl
rubygem-bundler
rubygem-json
rubygem-bigdecimal
ruby-irb
ruby-help
ruby-devel
ruby-debugsource
ruby-debuginfo
ruby
rubygem-rexml
rubygems-devel
rubygems
rubygem-psych
rubygem-test-unit
ruby-doc
ruby-default-gems
ruby-libs
ruby-bundled-gems
rubygem-minitest
rubygem-rdoc
rubygem-rake

How to mitigate CVE-2025-43857

Install updates from vendor's website.

net-imap - addressed in versions 0.2.5, 0.3.9, 0.4.20, 0.5.7
Astronomer with IBM - update to 1.0.1
rubygem-rss - update to 0.2.9-143
rubygem-rss - update to 0.3.1-5
rubygem-io-console - update to 0.5.7-143
rubygem-io-console - update to 0.7.1-5
rubygem-typeprof - update to 0.15.2-143
rubygem-typeprof - update to 0.21.9-5
rubygem-rbs - update to 1.4.0-143
rubygem-did_you_mean - update to 1.5.0-143
rubygem-racc - update to 1.7.3-5
rubygem-irb - update to 1.13.1-5
rubygem-power_assert - update to 2.0.3-5
rubygem-openssl - update to 2.2.1-143
rubygem-bundler - update to 2.2.32-143
rubygem-json - update to 2.5.1-143
rubygem-bundler - update to 2.5.22-5
rubygem-json - update to 2.7.2-5
rubygem-bigdecimal - update to 3.0.0-143
ruby-irb - update to 3.0.3-143
ruby-help - update to 3.0.3-143
ruby-devel - update to 3.0.3-143
ruby-debugsource - update to 3.0.3-143
ruby-debuginfo - update to 3.0.3-143
ruby - update to 3.0.3-143
rubygem-bigdecimal - update to 3.1.5-5
rubygem-rexml - update to 3.2.5-143
rubygems-devel - update to 3.2.32-143
rubygems - update to 3.2.32-143
rubygem-psych - update to 3.3.2-143
rubygem-test-unit - update to 3.3.7-143
ruby - update to 3.3.9-5
rubygem-rexml - update to 3.3.9-5
ruby-doc - update to 3.3.9-5
ruby-default-gems - update to 3.3.9-5
ruby-libs - update to 3.3.9-5
ruby-devel - update to 3.3.9-5
ruby-bundled-gems - update to 3.3.9-5
rubygem-rbs - update to 3.4.0-5
rubygems - update to 3.5.22-5
rubygems-devel - update to 3.5.22-5
rubygem-test-unit - update to 3.6.1-5
rubygem-psych - update to 5.1.2-5
rubygem-minitest - update to 5.14.2-143
rubygem-minitest - update to 5.20.0-5
rubygem-rdoc - update to 6.3.3-143
rubygem-rdoc - update to 6.6.3.1-5
rubygem-rake - update to 13.0.3-143
rubygem-rake - update to 13.1.0-5

External References

Related Security Bulletins