[Git][security-tracker-team/security-tracker][master] new python issue

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Mar 6 09:07:08 GMT 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8a89cdb6 by Moritz Muehlenhoff at 2026-03-06T10:06:44+01:00
new python issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -538,7 +538,19 @@ CVE-2026-2418 (The Login with Salesforce WordPress plugin through 1.0.2 does not
 CVE-2026-2365 (The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cros ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-2297 (The import hook in CPython that handles legacy *.pyc files (Sourceless ...)
-	TODO: check
+	- python3.14 <unfixed>
+	- python3.13 <unfixed>
+	- python3.11 <removed>
+	- python3.9 <removed>
+	- pypy3 <unfixed>
+	- python2.7 <removed>
+	- jython2.7 <removed>
+	NOTE: https://github.com/python/cpython/issues/145506
+	NOTE: https://github.com/python/cpython/pull/145507
+	NOTE: https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e (main)
+	NOTE: https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86 (3.14)
+	NOTE: https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e (3.13)
+	NOTE: https://github.com/python/cpython/pull/145515 (pull request for 3.11)
 CVE-2026-29128 (IDC SFX2100 Satellite Receiver firmware ships with multiple daemon con ...)
 	NOT-FOR-US: IDC SFX2100 Satellite Receiver firmware
 CVE-2026-29127 (The IDC SFX2100 Satellite Receiver sets overly permissive file system  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a89cdb65d68a5f58d079ad2214a76e79ea96948

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a89cdb65d68a5f58d079ad2214a76e79ea96948
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260306/b2586cd2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list