[Git][security-tracker-team/security-tracker][master] pypy3 status updates

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 23 08:54:53 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cf01f59f by Moritz Muehlenhoff at 2026-09-23T09:54:41+02:00
pypy3 status updates

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41886,9 +41886,7 @@ CVE-2026-19672 (The tarfile module's tar and data  extraction filters created di
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <not-affected> (extraction filters (PEP 706) absent in 3.11.2)
 	- python3.9 <not-affected> (extraction filters (PEP 706) absent in 3.9.2)
-	- pypy3 <unfixed>
-	[trixie] - pypy3 <no-dsa> (Minor issue)
-	[bookworm] - pypy3 <not-affected> (extraction filters (PEP 706) absent in stdlib 3.9.16)
+	- pypy3 <not-affected> (extraction filters (PEP 706) absent in stdlib 3.11)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/
 	NOTE: https://github.com/python/cpython/issues/155999
 	NOTE: https://github.com/python/cpython/pull/156000
@@ -101913,7 +101911,7 @@ CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar'  filter could be b
 	[bullseye] - python3.9 <postponed> (Minor issue)
 	- python2.7 <removed>
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
-	- pypy3 <unfixed> (bug #1141533)
+	- pypy3 8.0.0+dfsg-1 (bug #1141533)
 	[trixie] - pypy3 <no-dsa> (Minor issue)
 	[bookworm] - pypy3 <not-affected> (Extraction filters (PEP 706) absent in the embedded CPython stdlib; tarfile.extractall() has no filter parameter)
 	[bullseye] - pypy3 <not-affected> (Extraction filters (PEP 706) absent in the embedded CPython stdlib; tarfile.extractall() has no filter parameter)
@@ -101922,6 +101920,7 @@ CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar'  filter could be b
 	NOTE: https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df (v3.15.0b4)
 	NOTE: https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde (v3.13.15)
+	NOTE: https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9 (v3.11.16)
 CVE-2026-55556 (Rsyslog is a rocket-fast system for log processing. From 8.2110.0 unti ...)
 	- rsyslog 8.2604.0-1 (unimportant)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/06/23/4
@@ -169599,7 +169598,7 @@ CVE-2025-69534 (Python-Markdown version 3.8 contain a vulnerability where malfor
 	[bookworm] - python3.11 <no-dsa> (Minor issue)
 	- python3.9 <removed>
 	[bullseye] - python3.9 <postponed> (Minor issue, DoS)
-	- pypy3 <unfixed> (bug #1141532)
+	- pypy3 8.0.0+dfsg-1 (bug #1141532)
 	[trixie] - pypy3 <no-dsa> (Minor issue)
 	[bookworm] - pypy3 <no-dsa> (Minor issue)
 	[bullseye] - pypy3 <postponed> (Minor issue)
@@ -187775,7 +187774,7 @@ CVE-2025-12781 (When passing data to the b64decode(), standard_b64decode(), and
 	- python3.9 <removed>
 	[bullseye] - python3.9 <ignored> (Minor issue, no fix, only additional warnings)
 	- pypy3 <unfixed> (bug #1135117)
-	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[trixie] - pypy3 <ignored> (Not backported to older Python releases due to compat concerns)
 	[bookworm] - pypy3 <no-dsa> (Minor issue)
 	[bullseye] - pypy3 <ignored> (Minor issue, no fix, only additional warnings)
 	NOTE: https://github.com/python/cpython/issues/125346
@@ -188178,7 +188177,7 @@ CVE-2025-15367 (The poplib module, when passed a user-controlled command, can ha
 	- python3.9 <removed>
 	[bullseye] - python3.9 <ignored> (Not backported to older Python releases due to compat concerns, reverted in DLA-4532-1)
 	- pypy3 <unfixed> (bug #1141535)
-	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[trixie] - pypy3 <ignored> (Not backported to older Python releases due to compat concerns)
 	[bookworm] - pypy3 <no-dsa> (Minor issue)
 	[bullseye] - pypy3 <postponed> (Minor issue)
 	- python2.7 <removed>
@@ -188201,7 +188200,7 @@ CVE-2025-15366 (The imaplib module, when passed a user-controlled command, can h
 	- python3.9 <removed>
 	[bullseye] - python3.9 <ignored> (Not backported to older Python releases due to compat concerns, reverted in DLA-4532-1)
 	- pypy3 <unfixed> (bug #1141525)
-	[trixie] - pypy3 <no-dsa> (Minor issue)
+	[trixie] - pypy3 <ignored> (Not backported to older Python releases due to compat concerns)
 	[bookworm] - pypy3 <no-dsa> (Minor issue)
 	[bullseye] - pypy3 <postponed> (Minor issue)
 	- python2.7 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf01f59fa0635fbe8609efb8ed267c594d4ffcff

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf01f59fa0635fbe8609efb8ed267c594d4ffcff
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/ceb120ae/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list