# Nokogiri security update v1.11.4

**URL:** <https://rubytalk.org/t/nokogiri-security-update-v1-11-4/75467>\
**Category:** ruby-talk\
**Created:** [14 May 2021 23:37 UTC](https://rubytalk.org/t/nokogiri-security-update-v1-11-4/75467 "2021-05-14T23:37:39Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_Dalessio1](https://yyz1.discourse-cdn.com/flex029/user_avatar/rubytalk.org/mike_dalessio1/32/1903_2.png) [@Mike\_Dalessio1](https://rubytalk.org/u/Mike_Dalessio1)\
**Post date:** [14 May 2021 23:37 UTC](https://rubytalk.org/t/nokogiri-security-update-v1-11-4/75467/1 "2021-05-14T23:37:39Z")

</div>

Nokogiri v1.11.4 was released on 2021-05-14, which contains an updated  
version of libxml2 that addresses several upstream CVEs.

These CVEs are fully described at  
[Update packaged libxml2 from 2.9.10 to 2.9.12 · Advisory · sparklemotion/nokogiri · GitHub](https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-7rrm-v45f-jp64).  
That security advisory is reproduced here for your convenience.

> **···**
>
> ---
> 
> Summary
> 
> Nokogiri v1.11.4 updates the vendored libxml2 from v2.9.10 to v2.9.12 which  
> addresses:
> 
> &nbsp;&nbsp;&nbsp;- CVE-2019-20388 \<[CVE-2019-20388 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2019-20388)\> (Medium  
> &nbsp;&nbsp;&nbsp;severity)  
> &nbsp;&nbsp;&nbsp;- CVE-2020-24977 \<[CVE-2020-24977 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2020-24977)\> (Medium  
> &nbsp;&nbsp;&nbsp;severity)  
> &nbsp;&nbsp;&nbsp;- CVE-2021-3517 \<[CVE-2021-3517 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3517)\> (Medium  
> &nbsp;&nbsp;&nbsp;severity)  
> &nbsp;&nbsp;&nbsp;- CVE-2021-3518 \<[CVE-2021-3518 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3518)\> (Medium  
> &nbsp;&nbsp;&nbsp;severity)  
> &nbsp;&nbsp;&nbsp;- CVE-2021-3537 \<[CVE-2021-3537 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3537)\> (Low  
> &nbsp;&nbsp;&nbsp;severity)  
> &nbsp;&nbsp;&nbsp;- CVE-2021-3541 \<[CVE-2021-3541 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3541)\> (Low  
> &nbsp;&nbsp;&nbsp;severity)
> 
> Note that two additional CVEs were addressed upstream but are not relevant  
> to this release. CVE-2021-3516  
> \<[CVE-2021-3516 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3516)\> via xmllint is not present  
> in Nokogiri, and CVE-2020-7595  
> \<[CVE-2020-7595 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2020-7595)\> has been patched in Nokogiri  
> since v1.10.8 (see #1992  
> \<[Investigate libxml2 vulnerabilities patched in USN-4274-1 · Issue #1992 · sparklemotion/nokogiri · GitHub](https://github.com/sparklemotion/nokogiri/issues/1992)\>).
> 
> Please note that this advisory only applies to the CRuby implementation of  
> Nokogiri \< 1.11.4, and only if the packaged version of libxml2 is being  
> used. If you've overridden defaults at installation time to use system  
> libraries instead of packaged libraries, you should instead pay attention  
> to your distro's libxml2 release announcements.  
> Mitigation
> 
> Upgrade to Nokogiri \>= 1.11.4.  
> Impact
> 
> I've done a brief analysis of the published CVEs that are addressed in this  
> upstream release. The libxml2 maintainers have not released a canonical set  
> of CVEs, and so this list is pieced together from secondary sources and may  
> be incomplete.
> 
> All information below is sourced from [security.archlinux.org](http://security.archlinux.org), which appears  
> to have the most up-to-date information as of this analysis.  
> CVE-2019-20388 \<[CVE-2019-20388 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2019-20388)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Medium  
> &nbsp;&nbsp;&nbsp;- Type: Denial of service  
> &nbsp;&nbsp;&nbsp;- Description: A memory leak was found in the xmlSchemaValidateStream  
> &nbsp;&nbsp;&nbsp;function of libxml2. Applications that use this library may be vulnerable  
> &nbsp;&nbsp;&nbsp;to memory not being freed leading to a denial of service.  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[Fix memory leak in xmlSchemaValidateStream (7ffcd44d) · Commits · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/commit/7ffcd44d7e6c46704f8af0321d9314cd26e0e18a)
> 
> Verified that the fix commit first appears in v2.9.11. It seems possible  
> that this issue would be present in programs using Nokogiri \< v1.11.4.  
> CVE-2020-7595 \<[CVE-2020-7595 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2020-7595)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Medium  
> &nbsp;&nbsp;&nbsp;- Type: Denial of service  
> &nbsp;&nbsp;&nbsp;- Description: xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10  
> &nbsp;&nbsp;&nbsp;has an infinite loop in a certain end-of-file situation.  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5](https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c8907645d2e155f0d89d4d9895ac5112b5)
> 
> This has been patched in Nokogiri since v1.10.8 (see #1992  
> \<[Investigate libxml2 vulnerabilities patched in USN-4274-1 · Issue #1992 · sparklemotion/nokogiri · GitHub](https://github.com/sparklemotion/nokogiri/issues/1992)\>).  
> CVE-2020-24977 \<[CVE-2020-24977 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2020-24977)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Medium  
> &nbsp;&nbsp;&nbsp;- Type: Information disclosure  
> &nbsp;&nbsp;&nbsp;- Description: GNOME project libxml2 \<= 2.9.10 has a global buffer  
> &nbsp;&nbsp;&nbsp;over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c.  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[Fix out-of-bounds read with 'xmllint --htmlout' (50f06b3e) · Commits · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/commit/50f06b3efb638efb0abd95dc62dca05ae67882c2)
> 
> Verified that the fix commit first appears in v2.9.11. It seems possible  
> that this issue would be present in programs using Nokogiri \< v1.11.4.  
> CVE-2021-3516 \<[CVE-2021-3516 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3516)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Medium  
> &nbsp;&nbsp;&nbsp;- Type: Arbitrary code execution (no remote vector)  
> &nbsp;&nbsp;&nbsp;- Description: A use-after-free security issue was found libxml2 before  
> &nbsp;&nbsp;&nbsp;version 2.9.11 when "xmllint --html --push" is used to process crafted  
> &nbsp;&nbsp;&nbsp;files.  
> &nbsp;&nbsp;&nbsp;- Issue: [heap-use-after-free in entities.c:621 (#230) · Issues · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/-/issues/230)  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[Fix use-after-free with `xmllint --html --push` (1358d157) · Commits · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/-/commit/1358d157d0bd83be1dfe356a69213df9fac0b539)
> 
> Verified that the fix commit first appears in v2.9.11. This vector does not  
> exist within Nokogiri, which does not ship xmllint.  
> CVE-2021-3517 \<[CVE-2021-3517 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3517)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Medium  
> &nbsp;&nbsp;&nbsp;- Type: Arbitrary code execution  
> &nbsp;&nbsp;&nbsp;- Description: A heap-based buffer overflow was found in libxml2 before  
> &nbsp;&nbsp;&nbsp;version 2.9.11 when processing truncated UTF-8 input.  
> &nbsp;&nbsp;&nbsp;- Issue: [heap-buffer-overflow in entities.c:621 (#235) · Issues · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/-/issues/235)  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[Validate UTF8 in xmlEncodeEntities (bf227135) · Commits · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/-/commit/bf22713507fe1fc3a2c4b525cf0a88c2dc87a3a2)
> 
> Verified that the fix commit first appears in v2.9.11. It seems possible  
> that this issue would be present in programs using Nokogiri \< v1.11.4.  
> CVE-2021-3518 \<[CVE-2021-3518 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3518)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Medium  
> &nbsp;&nbsp;&nbsp;- Type: Arbitrary code execution  
> &nbsp;&nbsp;&nbsp;- Description: A use-after-free security issue was found in libxml2  
> &nbsp;&nbsp;&nbsp;before version 2.9.11 in xmlXIncludeDoProcess() in xinclude.c when  
> &nbsp;&nbsp;&nbsp;processing crafted files.  
> &nbsp;&nbsp;&nbsp;- Issue: [heap-use-after-free in xinclude.c:2433 (#237) · Issues · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/-/issues/237)  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[Fix user-after-free with `xmllint --xinclude --dropdtd` (1098c30a) · Commits · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/-/commit/1098c30a040e72a4654968547f415be4e4c40fe7)
> 
> Verified that the fix commit first appears in v2.9.11. It seems possible  
> that this issue would be present in programs using Nokogiri \< v1.11.4.  
> CVE-2021-3537 \<[CVE-2021-3537 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3537)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Low  
> &nbsp;&nbsp;&nbsp;- Type: Denial of service  
> &nbsp;&nbsp;&nbsp;- Description: It was found that libxml2 before version 2.9.11 did not  
> &nbsp;&nbsp;&nbsp;propagate errors while parsing XML mixed content, causing a NULL  
> &nbsp;&nbsp;&nbsp;dereference. If an untrusted XML document was parsed in recovery mode and  
> &nbsp;&nbsp;&nbsp;post-validated, the flaw could be used to crash the application.  
> &nbsp;&nbsp;&nbsp;- Issue: [CWE-476 NULL pointer dereference in valid.c:729 in xmlValidBuildAContentModel (#243) · Issues · GNOME / libxml2 · GitLab](https://gitlab.gnome.org/GNOME/libxml2/-/issues/243)  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[https://gitlab.gnome.org/GNOME/libxml2/-/commit/babe75030c7f64a37826bb3342317134568bef61](https://gitlab.gnome.org/GNOME/libxml2/-/commit/babe75030c7f64a37826bb3342317134568bef61)
> 
> Verified that the fix commit first appears in v2.9.11. It seems possible  
> that this issue would be present in programs using Nokogiri \< v1.11.4.  
> CVE-2021-3541 \<[CVE-2021-3541 - libxml2 - Arch Linux](https://security.archlinux.org/CVE-2021-3541)\>
> 
> &nbsp;&nbsp;&nbsp;- Severity: Low  
> &nbsp;&nbsp;&nbsp;- Type: Denial of service  
> &nbsp;&nbsp;&nbsp;- Description: A security issue was found in libxml2 before version  
> &nbsp;&nbsp;&nbsp;2.9.11. Exponential entity expansion attack its possible bypassing all  
> &nbsp;&nbsp;&nbsp;existing protection mechanisms and leading to denial of service.  
> &nbsp;&nbsp;&nbsp;- Fixed:  
> &nbsp;&nbsp;&nbsp;[https://gitlab.gnome.org/GNOME/libxml2/-/commit/8598060bacada41a0eb09d95c97744ff4e428f8e](https://gitlab.gnome.org/GNOME/libxml2/-/commit/8598060bacada41a0eb09d95c97744ff4e428f8e)
> 
> Verified that the fix commit first appears in v2.9.11. It seems possible  
> that this issue would be present in programs using Nokogiri \< v1.11.4,  
> however Nokogiri's default parse options prevent the attack from succeeding  
> (it is necessary to opt into DTDLOAD which is off by default).
