[Git][security-tracker-team/security-tracker][master] remove CVE-2026-3276 for pypy, doesn't use the cpython implementation

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Jul 5 21:38:08 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6da8b873 by Moritz Muehlenhoff at 2026-07-05T22:37:21+02:00
remove CVE-2026-3276 for pypy, doesn't use the cpython implementation

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -23263,10 +23263,6 @@ CVE-2026-3276 (unicodedata.normalize() can take excessive CPU time when processi
 	[bullseye] - python3.9 <postponed> (Minor issue)
 	- python2.7 <removed>
 	[bullseye] - python2.7 <end-of-life> (not supported in bullseye)
-	- pypy3 <unfixed>
-	[trixie] - pypy3 <no-dsa> (Minor issue)
-	[bookworm] - pypy3 <no-dsa> (Minor issue)
-	[bullseye] - pypy3 <postponed> (minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/06/03/15
 	NOTE: https://github.com/python/cpython/pull/149080
 	NOTE: https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f (main)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6da8b87358fcc76909738a4477175e750fe23073

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6da8b87358fcc76909738a4477175e750fe23073
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260705/58e5c36a/attachment.htm>


More information about the debian-security-tracker-commits mailing list