Bug 33146 - python-gunicorn new security issue CVE-2024-1135
Summary: python-gunicorn new security issue CVE-2024-1135
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-04-26 16:39 CEST by Nicolas Salguero
Modified: 2024-06-24 21:05 CEST (History)
3 users (show)

See Also:
Source RPM: python-gunicorn-21.2.0-2.mga10.src.rpm
CVE: CVE-2024-1135
Status comment:


Attachments

Description Nicolas Salguero 2024-04-26 16:39:13 CEST
openSUSE has issued an advisory on April 26:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/T3JUAVTE5DCLOJLFBSIK3OPDOUIF7BMB/

According to Debian, the commit that solves the problem is:
https://github.com/benoitc/gunicorn/commit/ac29c9b0a758d21f1e0fb3b3457239e523fa9f1d
That commit is included into version 22.0.0.

Mageia 9 is also affected.
Nicolas Salguero 2024-04-26 16:39:38 CEST

Source RPM: (none) => python-gunicorn-21.2.0-2.mga10.src.rpm
CVE: (none) => CVE-2024-1135
Whiteboard: (none) => MGA9TOO
Status comment: (none) => Fixed upstream in 22.0.0 and patch available from upstream

Comment 1 Lewis Smith 2024-04-28 20:44:38 CEST
Assigning to Python people.

Assignee: bugsquad => python

Comment 2 papoteur 2024-06-23 19:39:28 CEST
Updated in cauldron

Submitting:
SRPMS:
python-gunicorn-22.0.0-1.mga9
RPMS:
python3-gunicorn-22.0.0-1.mga9.noarch

Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Status comment: Fixed upstream in 22.0.0 and patch available from upstream => (none)
CC: (none) => yvesbrungard
Assignee: python => qa-bugs

katnatek 2024-06-23 21:02:04 CEST

Keywords: (none) => advisory

Comment 3 katnatek 2024-06-23 21:11:47 CEST
RH mageia 9 x86_64

The usual "I don't know how to test" install current/update to testing test  

LC_ALL=C urpmi python3-gunicorn

    https://mirror.math.princeton.edu/pub/mageia/distrib/9/x86_64/media/core/release/python3-gunicorn-20.1.0-3.mga9.noarch.rpm
installing python3-gunicorn-20.1.0-3.mga9.noarch.rpm from /var/cache/urpmi/rpms                                                     
Preparing...                     ##################################################################################################
      1/1: python3-gunicorn      ##################################################################################################

LC_ALL=C urpmi --auto --auto-update
medium "QA Testing (32-bit)" is up-to-date
medium "QA Testing (64-bit)" is up-to-date
medium "Core Release (distrib1)" is up-to-date
medium "Core Updates (distrib3)" is up-to-date
medium "Nonfree Release (distrib11)" is up-to-date
medium "Nonfree Updates (distrib13)" is up-to-date
medium "Tainted Release (distrib21)" is up-to-date
medium "Tainted Updates (distrib23)" is up-to-date
medium "Core 32bit Release (distrib31)" is up-to-date
medium "Core 32bit Updates (distrib32)" is up-to-date
medium "Nonfree 32bit Release (distrib36)" is up-to-date
medium "Tainted 32bit Release (distrib41)" is up-to-date
medium "Tainted 32bit Updates (distrib42)" is up-to-date

installing python3-gunicorn-22.0.0-1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: python3-gunicorn      ##################################################################################################

Feel free of provide/suggest other test, not previous rounds of this package
Comment 4 papoteur 2024-06-23 22:02:01 CEST
Installed on my RPI-aarch64.
Restart a gunicorn service, serving madb.
All seems OK.
Comment 5 katnatek 2024-06-24 01:07:44 CEST
(In reply to papoteur from comment #4)
> Installed on my RPI-aarch64.
> Restart a gunicorn service, serving madb.
> All seems OK.

I guess this count as real case use, give OK

CC: (none) => andrewsfarm
Whiteboard: (none) => MGA9-64-OK

Comment 6 Thomas Andrews 2024-06-24 03:17:10 CEST
Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 7 Mageia Robot 2024-06-24 21:05:06 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0236.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.