Ubuntu has issued an advisory on November 28: https://usn.ubuntu.com/4204-1/ Mageia 7 is also affected.
Whiteboard: (none) => MGA7TOO
Done!
CC: (none) => geiger.david68210
Advisory: ======================== Updated python-psutil packages fix security vulnerability: Riccardo Schirone discovered that psutil incorrectly handled certain reference counting operations. An attacker could use this issue to cause psutil to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2019-18874). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18874 https://usn.ubuntu.com/4204-1/ ======================== Updated packages in core/updates_testing: ======================== python2-psutil-5.6.7-1.mga7 python3-psutil-5.6.7-1.mga7 from python-psutil-5.6.7-1.mga7.src.rpm
Whiteboard: MGA7TOO => (none)Assignee: bugsquad => qa-bugsVersion: Cauldron => 7
MGA7-64 Plasma on Lenovo B50 No installation issues. Used urpmq to find packages to test, picked terminator to test python2-psutil and glances for python3-psutil. Used strace to check the usage, both programs seemed to perform well, and the trace shows references to the packages under test. OK for me.
Whiteboard: (none) => MGA7-64-OKCC: (none) => herman.viaene
Validating. Advisory in Comment 2.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
CC: (none) => tmbKeywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2019-0370.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED