Bug 34007 - python3 new security issues CVE-2025-0938, CVE-2025-1795 and CVE-2024-9287
Summary: python3 new security issues CVE-2025-0938, CVE-2025-1795 and CVE-2024-9287
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Python Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 34285
Blocks:
  Show dependency treegraph
 
Reported: 2025-02-11 17:05 CET by Nicolas Salguero
Modified: 2025-11-13 08:28 CET (History)
0 users

See Also:
Source RPM: python3-3.10.11-1.3.mga9.src.rpm
CVE: CVE-2025-0938, CVE-2025-1795, CVE-2024-9287
Status comment: Patch available from upstream for CVE-2025-0938


Attachments

Comment 1 Nicolas Salguero 2025-02-11 17:09:31 CET
Fix for python 3.10: https://github.com/python/cpython/pull/129529

Status comment: (none) => Fixed upstream in 3.12.9 and patch available from upstream
CVE: (none) => CVE-2025-0938
Source RPM: (none) => python3-3.12.8-1.mga10.src.rpm, python3-3.10.11-1.3.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 2 Lewis Smith 2025-02-12 21:13:22 CET
Thanks for the patch ref.

Assignee: bugsquad => python

Nicolas Salguero 2025-03-14 10:34:39 CET

Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Source RPM: python3-3.12.8-1.mga10.src.rpm, python3-3.10.11-1.3.mga9.src.rpm => python3-3.10.11-1.3.mga9.src.rpm
Summary: python3 new security issue CVE-2025-0938 => python3 new security issues CVE-2025-0938 and CVE-2025-1795

Comment 3 Nicolas Salguero 2025-03-14 10:36:41 CET
openSUSE has issued an advisory on March 12:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/NNC4GZYGFZ76A7NUZ5BG2CMGVR32LXCG/

For python 3.10, I could not find the patch for CVE-2025-1795.

Cauldron is not affected.

Status comment: Fixed upstream in 3.12.9 and patch available from upstream => Patch available from upstream for CVE-2025-0938
CVE: CVE-2025-0938 => CVE-2025-0938, CVE-2025-1795

Comment 4 Nicolas Salguero 2025-05-07 15:51:09 CEST
Ubuntu has issued an advisory on May 6:
https://ubuntu.com/security/notices/USN-7488-1

Upstream patch for CVE-2024-9287:
https://github.com/python/cpython/commit/9286ab3a107ea41bd3f3c3682ce2512692bdded8

CVE: CVE-2025-0938, CVE-2025-1795 => CVE-2025-0938, CVE-2025-1795, CVE-2024-9287
Summary: python3 new security issues CVE-2025-0938 and CVE-2025-1795 => python3 new security issues CVE-2025-0938, CVE-2025-1795 and CVE-2024-9287

Nicolas Salguero 2025-11-10 10:51:17 CET

Depends on: (none) => 34285

Comment 5 Nicolas Salguero 2025-11-13 08:28:26 CET
Fixed in bug 34285.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.