[Git][security-tracker-team/security-tracker][master] update pypy3 status
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 23 16:45:33 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
874b2bdf by Moritz Muehlenhoff at 2026-09-23T17:42:11+02:00
update pypy3 status
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -95390,7 +95390,7 @@ CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not pa
- python3.9 <not-affected> (extraction filters (PEP 706) absent in 3.9.2; extract() has no filter parameter)
- python2.7 <not-affected> (extraction filters (PEP 706) absent in py2; extract() has no filter parameter)
- jython <not-affected> (extraction filters/PEP 706 absent in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
- - pypy3 <unfixed> (bug #1141531)
+ - pypy3 8.0.0+dfsg-1 (bug #1141531)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <not-affected> (Vulnerable code backported down to stdlib-3.9.17; embedding 3.6.16)
[bullseye] - pypy3 <not-affected> (Vulnerable code backported down to stdlib-3.9.17; embedding 3.6.9)
@@ -95400,6 +95400,7 @@ CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not pa
NOTE: https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301 (v3.15.0b4)
NOTE: https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0 (v3.14.7)
NOTE: https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e (v3.13.15)
+ NOTE: https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44 (v3.11.16)
NOTE: Same code situation as with CVE-2025-4435.
CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ. An authentic ...)
- activemq <unfixed> (bug #1141385)
@@ -102126,7 +102127,7 @@ CVE-2026-0864 (When using the "configparser" module to write configuration files
[bullseye] - python3.9 <postponed> (Minor issue)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- - pypy3 <unfixed> (bug #1141524)
+ - pypy3 8.0.0+dfsg-1 (bug #1141524)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue; configparser._write_section() escapes only LF, so CR/CRLF in a value injects config lines on write-back)
[bullseye] - pypy3 <postponed> (Minor issue; configparser._write_section() escapes only LF, so CR/CRLF in a value injects config lines on write-back)
@@ -102138,6 +102139,7 @@ CVE-2026-0864 (When using the "configparser" module to write configuration files
NOTE: https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f (main)
NOTE: https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98 (v3.14.7)
NOTE: https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8 (v3.13.15)
+ NOTE: https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908 (v3.11.16)
CVE-2025-71382 (MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerabili ...)
- mupdf 1.27.0+ds1-2
[trixie] - mupdf <no-dsa> (Minor issue)
@@ -128407,7 +128409,7 @@ CVE-2026-8328 (The ftpcp() function in Lib/ftplib.py was not updated when CVE-2
[bullseye] - python3.9 <postponed> (Minor issue, port scanning in specific scenario)
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (not supported in bullseye)
- - pypy3 <unfixed> (bug #1141526)
+ - pypy3 8.0.0+dfsg-1 (bug #1141526)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <no-dsa> (Minor issue)
[bullseye] - pypy3 <postponed> (Minor issue)
@@ -128415,6 +128417,7 @@ CVE-2026-8328 (The ftpcp() function in Lib/ftplib.py was not updated when CVE-2
NOTE: https://github.com/python/cpython/pull/149648
NOTE: https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9 (main branch)
NOTE: https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763 (3.13 branch)
+ NOTE: https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb (v3.11.16)
CVE-2026-8280 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
- gitlab <removed>
CVE-2026-8181 (The Burst Statistics \u2013 Privacy-Friendly WordPress Analytics (Goog ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/874b2bdf3307d79327f46b4ba017b25062ce39fa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/874b2bdf3307d79327f46b4ba017b25062ce39fa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/ab502e7f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list