Asymmetric Resource Consumption (Amplification) in net-imap - CVE-2025-25186
Published: June 27, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in `net-imap`'s response parser. At any time while the client is connected, a malicious server can send can send highly compressed `uid-set` data which is automatically read by the client's receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM Cloud Pak for Watson AIOps
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
openEuler
Fedora
rubygem-rss
rubygem-abrt
rubygem-abrt-doc
rubygem-mysql2
rubygem-mysql2-doc
rubygem-io-console
rubygem-typeprof
rubygem-pg
rubygem-pg-doc
rubygem-did_you_mean
rubygem-racc
rubygem-irb
rubygem-power_assert
rubygem-bundler
rubygem-json
rubygem-rbs
rubygem-openssl
rubygem-bigdecimal
ruby-debugsource
ruby-devel
ruby-help
ruby-irb
ruby-debuginfo
ruby-bundled-gems
ruby
rubygem-rexml
ruby-default-gems
ruby-doc
ruby-libs
ruby (Red Hat package)
rubygems-devel
rubygems
rubygem-test-unit
rubygem-psych
rubygem-minitest
rubygem-rdoc
rubygem-rake
OpenShift Logging
How to mitigate CVE-2025-25186
IBM Cloud Pak for Watson AIOps - update to 4.10.0
rubygem-rss - update to 0.2.9-148
rubygem-rss - update to 0.3.1-4
rubygem-abrt - update to 0.4.0-1
rubygem-abrt-doc - update to 0.4.0-1
rubygem-mysql2 - update to 0.5.5-1
rubygem-mysql2-doc - update to 0.5.5-1
rubygem-io-console - update to 0.6.0-148
rubygem-io-console - update to 0.7.1-4
rubygem-typeprof - update to 0.21.3-148
rubygem-typeprof - update to 0.21.9-4
rubygem-pg - update to 1.5.4-1
rubygem-pg-doc - update to 1.5.4-1
rubygem-did_you_mean - update to 1.6.3-148
rubygem-racc - update to 1.7.3-4
rubygem-irb - update to 1.13.1-4
rubygem-power_assert - update to 2.0.3-4
rubygem-bundler - update to 2.5.22-4
rubygem-json - update to 2.6.3-148
rubygem-json - update to 2.7.2-4
rubygem-rbs - update to 2.8.2-148
rubygem-openssl - update to 3.1.0-148
rubygem-bigdecimal - update to 3.1.3-148
rubygem-bigdecimal - update to 3.1.5-4
ruby-debugsource - update to 3.2.2-148
ruby-devel - update to 3.2.2-148
ruby-help - update to 3.2.2-148
ruby-irb - update to 3.2.2-148
ruby-debuginfo - update to 3.2.2-148
ruby-bundled-gems - update to 3.2.2-148
ruby - update to 3.2.2-148
rubygem-rexml - update to 3.2.5-148
ruby-default-gems - update to 3.3.8-4
ruby-doc - update to 3.3.8-4
ruby - update to 3.3.8-4
ruby-bundled-gems - update to 3.3.8-4
ruby-devel - update to 3.3.8-4
ruby-libs - update to 3.3.8-4
ruby (Red Hat package) - update to 3.3.8-10.el10_0
ruby - addressed in versions 3.3.8-19.fc40, 3.3.8-19.fc41
rubygem-rexml - update to 3.3.9-4
rubygem-rbs - update to 3.4.0-4
rubygems-devel - update to 3.4.10-148
rubygems - update to 3.4.10-148
rubygem-test-unit - update to 3.5.7-148
rubygems - update to 3.5.22-4
rubygems-devel - update to 3.5.22-4
rubygem-test-unit - update to 3.6.1-4
rubygem-psych - update to 5.0.1-148
rubygem-psych - update to 5.1.2-4
OpenShift Logging - update to 5.9.13
rubygem-minitest - update to 5.16.3-148
rubygem-minitest - update to 5.20.0-4
rubygem-rdoc - update to 6.5.0-148
rubygem-rdoc - update to 6.6.3.1-4
rubygem-rake - update to 13.0.6-148
rubygem-rake - update to 13.1.0-4
External References
- https://github.com/ruby/net-imap/commit/70e3ddd071a94e450b3238570af482c296380b35
- https://github.com/ruby/net-imap/commit/c8c5a643739d2669f0c9a6bb9770d0c045fd74a3
- https://github.com/ruby/net-imap/commit/cb92191b1ddce2d978d01b56a0883b6ecf0b1022
- https://github.com/ruby/net-imap/security/advisories/GHSA-7fc5-f82f-cx69
Related Security Bulletins
- Asymmetric Resource Consumption (Amplification) in ruby net-imap
- Fedora 41 update for ruby
- Fedora 40 update for ruby
- openEuler 24.03 LTS SP1 update for ruby
- openEuler 24.03 LTS update for ruby
- Multiple vulnerabilities in OpenShift Logging 5.9
- Red Hat Enterprise Linux 10 update for ruby
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Red Hat Enterprise Linux 8 update for the ruby:3.3 module
- Anolis OS update for ruby:3.3 module