[Git][security-tracker-team/security-tracker][master] pypy3 updates
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 23 13:50:28 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0e8327f0 by Moritz Muehlenhoff at 2026-09-23T14:50:14+02:00
pypy3 updates
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -69201,7 +69201,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
[bullseye] - python3.9 <postponed> (Minor issue)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- - pypy3 <unfixed> (bug #1147726)
+ - pypy3 8.0.0+dfsg-1 (bug #1147726)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue)
[bullseye] - pypy3 <postponed> (Minor issue)
@@ -101558,7 +101558,7 @@ CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming
[bullseye] - python3.9 <postponed> (Minor issue)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- - pypy3 <unfixed> (bug #1141534)
+ - pypy3 8.0.0+dfsg-1 (bug #1141534)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue; CPU DoS in tarfile._Stream.seek() looping over attacker-declared block count past EOF, needs a crafted archive opened in streaming mode)
[bullseye] - pypy3 <postponed> (Minor issue; CPU DoS in tarfile._Stream.seek() looping over attacker-declared block count past EOF, needs a crafted archive opened in streaming mode)
@@ -101566,6 +101566,7 @@ CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming
NOTE: https://github.com/python/cpython/issues/151981
NOTE: https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec (v3.14.7)
NOTE: https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9 (v3.13.15)
+ NOTE: https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21 (v3.11.16)
CVE-2026-11820 (A flaw was found in the community.general Ansible collection's nexmo m ...)
NOT-FOR-US: Red Hat
CVE-2026-11819 (Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM \u2014 ...)
@@ -114451,7 +114452,7 @@ CVE-2026-7774 (tarfile.data_filter could be bypassed using crafted link entries,
- python3.11 <not-affected> (Vulnerable code didn't get backported to the version in Bookworm)
- python3.9 <not-affected> (Vulnerable code got backported to 3.9.17, but dropped from sid with 3.9.13)
- python2.7 <not-affected> (Vulnerable code didn't get backported to py2)
- - pypy3 <unfixed> (bug #1141492)
+ - pypy3 8.0.0+dfsg-1 (bug #1141492)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <not-affected> (Vulnerable code backported down to stdlib-3.9.17; embedding 3.6.16)
[bullseye] - pypy3 <not-affected> (Vulnerable code backported down to stdlib-3.9.17; embedding 3.6.9)
@@ -114462,6 +114463,7 @@ CVE-2026-7774 (tarfile.data_filter could be bypassed using crafted link entries,
NOTE: https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf (3.14 branch)
NOTE: https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2 (3.13 branch)
NOTE: https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d (3.12 branch)
+ NOTE: https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc (v3.11.16)
NOTE: Same code situation as with CVE-2025-4435.
CVE-2026-7764 (An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel ...)
NOT-FOR-US: Morse Micro HaLowLink 2 software
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0e8327f0748b99b629143d911e5c8d7ec7fdab60
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0e8327f0748b99b629143d911e5c8d7ec7fdab60
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/fdde85ed/attachment.htm>
More information about the debian-security-tracker-commits
mailing list