[Git][security-tracker-team/security-tracker][master] Add CVE-2025-58068/python-eventlet

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 30 09:29:25 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c0aaf924 by Salvatore Bonaccorso at 2025-08-30T10:29:01+02:00
Add CVE-2025-58068/python-eventlet

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -28,7 +28,10 @@ CVE-2025-58157 (gnark is a zero-knowledge proof system framework. In version 0.1
 CVE-2025-58156 (Centurion ERP is an ERP with a focus on ITSM and automation. In versio ...)
 	NOT-FOR-US: Centurion ERP
 CVE-2025-58068 (Eventlet is a concurrent networking library for Python. Prior to versi ...)
-	TODO: check
+	- python-eventlet <unfixed>
+	NOTE: https://github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7
+	NOTE: https://github.com/eventlet/eventlet/pull/1062
+	NOTE: https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb (0.40.3)
 CVE-2025-58067 (Basecamp's Google Sign-In adds Google sign-in to Rails applications. P ...)
 	NOT-FOR-US: Basecamp's Google Sign-In
 CVE-2025-58066 (nptd-rs is a tool for synchronizing your computer's clock, implementin ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0aaf9245b9c54937f6273aa68a2e4f37a53aa42

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c0aaf9245b9c54937f6273aa68a2e4f37a53aa42
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250830/086d7f06/attachment.htm>


More information about the debian-security-tracker-commits mailing list