SUSE has issued an advisory on November 1: https://lists.suse.com/pipermail/sle-security-updates/2024-November/019754.html
Status comment: (none) => Fixed upstream in 3.0.1 and patch available from openSUSESource RPM: (none) => python-waitress-3.0.0-1.mga10.src.rpm, python-waitress-2.1.2-1.mga9.src.rpmCVE: (none) => CVE-2024-49769Whiteboard: (none) => MGA9TOO
Patches in https://ftp.belnet.be//mirror/ftp.opensuse.org/opensuse/update/leap/15.5/sle/src/python-waitress-2.1.2-150400.12.7.1.src.rpm
CVE: CVE-2024-49769 => CVE-2024-49768, CVE-2024-49769Summary: python-waitress new security issue CVE-2024-49769 => python-waitress new security issues CVE-2024-49768 and CVE-2024-49769Status comment: Fixed upstream in 3.0.1 and patch available from openSUSE => Fixed upstream in 3.0.1 and patches available from openSUSE
Thanks for the patch ref. Assigning to Python group.
Assignee: bugsquad => python
Suggested advisory: ======================== The updated package fixes security vulnerabilities: Waitress has request processing race condition in HTTP pipelining with invalid first request. (CVE-2024-49768) Waitress has a denial of service leading to high CPU usage/resource exhaustion. (CVE-2024-49769) References: https://lists.suse.com/pipermail/sle-security-updates/2024-November/019754.html ======================== Updated package in core/updates_testing: ======================== python3-waitress-2.1.2-1.1.mga9 from SRPM: python-waitress-2.1.2-1.1.mga9.src.rpm
Assignee: python => qa-bugsSource RPM: python-waitress-3.0.0-1.mga10.src.rpm, python-waitress-2.1.2-1.mga9.src.rpm => python-waitress-2.1.2-1.mga9.src.rpmStatus: NEW => ASSIGNEDVersion: Cauldron => 9Whiteboard: MGA9TOO => (none)Status comment: Fixed upstream in 3.0.1 and patches available from openSUSE => (none)
Keywords: (none) => advisory
RH x86_64 installing python3-waitress-2.1.2-1.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/1: python3-waitress ################################################################################################## 1/1: removing python3-waitress-2.1.2-1.mga9.noarch ################################################################################################## Reference https://bugs.mageia.org/show_bug.cgi?id=30248#c3 OK on clean install
CC: (none) => andrewsfarmWhiteboard: (none) => MGA9-64-OK
Validating.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0053.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED