Fedora has issued an advisory on May 2: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWEI6NIHZ3G7DURDZVMRK7ZEFC2BTD3U/ The fix is: https://github.com/aio-libs/aiohttp/commit/28335525d1eac015a7e7584137678cbb6ff19397 Mageia 9 is also affected.
Whiteboard: (none) => MGA9TOOSource RPM: (none) => python-aiohttp-3.9.1-1.mga10.src.rpmCVE: (none) => CVE-2024-27306Status comment: (none) => Fixed upstream in 3.9.4 and patch available from upstream
wally is clearly the current maintainer for this SRPM, so assigning to you. Even v3.9.1 is quite recent; it has jumped several version quickly.
Assignee: bugsquad => jani.valimaa
I'm not maintaining any python pkg. Reassigning to bug squad.
Assignee: jani.valimaa => bugsquad
Sorry; thank you for saying so. Re-assigning generically to Python stack.
Assignee: bugsquad => python
Cauldron updated. python-aiohttp-3.9.5-1.mga10
Source RPM: python-aiohttp-3.9.1-1.mga10.src.rpm => python-aiohttp-3.8.3-3.mga9.src.rpmWhiteboard: MGA9TOO => (none)Version: Cauldron => 9CC: (none) => yvesbrungard
Submitting: SRPMS: python-aiohttp-3.8.3-3.mga9 RPMS: python3-aiohttp+speedups-3.8.3-3.mga9 python3-aiohttp-3.8.3-3.mga9.x86_64.rpm
Assignee: python => qa-bugsStatus comment: Fixed upstream in 3.9.4 and patch available from upstream => (none)
You have forgot the "%define subrel 1" for mga9!
CC: (none) => geiger.david68210
(In reply to David GEIGER from comment #6) > You have forgot the "%define subrel 1" for mga9! I must wait to new release to test and make advisory?
Indeed. Submitting: SRPMS: python-aiohttp-3.8.3-3.1.mga9 RPMS: python3-aiohttp+speedups-3.8.3-3.1.mga9 python3-aiohttp-3.8.3-3.1.mga9
Keywords: (none) => advisory
RH mageia 9 x86_64 Reference bug#28490 Install current version In one terminal python3 aio_http_server.py ======== Running on http://0.0.0.0:8080 ======== (Press CTRL+C to quit) In other terminal python3 aio_http_client.py Status: 200 Content-type: text/html; charset=utf-8 Body: <!doctype html> ... Open in the browser http://0.0.0.0:8080 Hello, Anonymous And in terminal 1 this appear (perhaps because I have https only mode enable) Traceback (most recent call last): File "/usr/lib64/python3.10/site-packages/aiohttp/web_protocol.py", line 332, in data_received messages, upgraded, tail = self._request_parser.feed_data(data) File "aiohttp/_http_parser.pyx", line 551, in aiohttp._http_parser.HttpParser.feed_data aiohttp.http_exceptions.BadStatusLine: 400, message="Bad status line 'Invalid method encountered'" LC_ALL=C urpmi --auto --auto-update medium "QA Testing (32-bit)" is up-to-date medium "QA Testing (64-bit)" is up-to-date medium "Core Release (distrib1)" is up-to-date medium "Core Updates (distrib3)" is up-to-date medium "Nonfree Release (distrib11)" is up-to-date medium "Nonfree Updates (distrib13)" is up-to-date medium "Tainted Release (distrib21)" is up-to-date medium "Tainted Updates (distrib23)" is up-to-date medium "Core 32bit Release (distrib31)" is up-to-date medium "Core 32bit Updates (distrib32)" is up-to-date medium "Nonfree 32bit Release (distrib36)" is up-to-date medium "Tainted 32bit Release (distrib41)" is up-to-date medium "Tainted 32bit Updates (distrib42)" is up-to-date installing python3-aiohttp+speedups-3.8.3-3.1.mga9.x86_64.rpm python3-aiohttp-3.8.3-3.1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/2: python3-aiohttp ################################################################################################## 2/2: python3-aiohttp+speedups ################################################################################################## 1/2: removing python3-aiohttp+speedups-3.8.3-3.mga9.x86_64 ################################################################################################## 2/2: removing python3-aiohttp-3.8.3-3.mga9.x86_64 ################################################################################################## Repeat the test all is the same except I not get the fail after open http://0.0.0.0:8080 Looks good to me
Whiteboard: (none) => MGA9-64-OKCC: (none) => andrewsfarm
Validating.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0235.html
Status: NEW => RESOLVEDResolution: (none) => FIXED