Bug 33436 - python3 new security issues CVE-2024-4032, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232
Summary: python3 new security issues CVE-2024-4032, CVE-2024-6923, CVE-2024-8088, CVE-...
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Python Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-25 10:27 CEST by Nicolas Salguero
Modified: 2024-09-05 16:08 CEST (History)
0 users

See Also:
Source RPM: python3-3.10.11-1.2.mga9.src.rpm
CVE: CVE-2024-4032, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232
Status comment:


Attachments

Description Nicolas Salguero 2024-07-25 10:27:20 CEST
RedHat has issued an advisory on July 23:
https://lwn.net/Articles/983060/
Nicolas Salguero 2024-07-25 10:27:44 CEST

Source RPM: (none) => python3-3.10.11-1.2.mga9.src.rpm
CVE: (none) => CVE-2024-4032

Comment 1 Lewis Smith 2024-07-25 22:31:27 CEST
This page:
 https://nvd.nist.gov/vuln/detail/CVE-2024-4032
lists 6 https://github.com/python/cpython/commit/ links which are patches. They look to be variations on the same theme...

Assignee: bugsquad => python

Comment 2 Nicolas Salguero 2024-09-02 11:00:32 CEST
CVE-2024-6923 was announced here:
https://openwall.com/lists/oss-security/2024/08/01/3

Summary: python3 new security issue CVE-2024-4032 => python3 new security issues CVE-2024-4032, CVE-2024-6923
Whiteboard: (none) => MGA9TOO
Version: 9 => Cauldron
CVE: CVE-2024-4032 => CVE-2024-4032, CVE-2024-6923

Comment 3 Nicolas Salguero 2024-09-02 11:15:05 CEST
CVE-2024-8088 was announced here:
https://openwall.com/lists/oss-security/2024/08/22/1

Summary: python3 new security issues CVE-2024-4032, CVE-2024-6923 => python3 new security issues CVE-2024-4032, CVE-2024-6923, CVE-2024-8088
CVE: CVE-2024-4032, CVE-2024-6923 => CVE-2024-4032, CVE-2024-6923, CVE-2024-8088

Comment 4 Nicolas Salguero 2024-09-05 16:08:39 CEST
CVE-2024-6232 was announced here:
https://www.openwall.com/lists/oss-security/2024/09/03/5

Summary: python3 new security issues CVE-2024-4032, CVE-2024-6923, CVE-2024-8088 => python3 new security issues CVE-2024-4032, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232
CVE: CVE-2024-4032, CVE-2024-6923, CVE-2024-8088 => CVE-2024-4032, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232


Note You need to log in before you can comment on or make changes to this bug.