Bug 35253 - python-pyasn1 new security issue CVE-2026-30922
Summary: python-pyasn1 new security issue CVE-2026-30922
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-03-23 09:33 CET by Nicolas Salguero
Modified: 2026-04-06 19:37 CEST (History)
3 users (show)

See Also:
Source RPM: python-pyasn1-0.4.8-6.1.mga9.src.rpm
CVE: CVE-2026-30922
Status comment:
herman.viaene: test_passed_mga9_64+


Attachments

Nicolas Salguero 2026-03-23 09:34:16 CET

Source RPM: (none) => python-pyasn1-0.6.1-3.mga10.src.rpm, python-pyasn1-0.4.8-6.1.mga9.src.rpm
CVE: (none) => CVE-2026-30922
Whiteboard: (none) => MGA9TOO
Status comment: (none) => Fixed upstream in 0.6.3
Flags: (none) => affects_mga9+

Comment 1 Nicolas Salguero 2026-03-23 09:58:44 CET
For Cauldron, I asked for a freeze move.

Flags: affects_mga9+ => (none)
Whiteboard: MGA9TOO => (none)
Source RPM: python-pyasn1-0.6.1-3.mga10.src.rpm, python-pyasn1-0.4.8-6.1.mga9.src.rpm => python-pyasn1-0.4.8-6.1.mga9.src.rpm
Version: Cauldron => 9

Comment 2 Lewis Smith 2026-03-24 21:19:26 CET
Just a version update.

Assignee: bugsquad => python

Comment 3 Nicolas Salguero 2026-03-31 15:29:57 CEST
Ubuntu has issued an advisory on March 30:
https://ubuntu.com/security/notices/USN-8129-1
Comment 4 Nicolas Salguero 2026-03-31 15:31:29 CEST
Suggested advisory:
========================

The updated package fixes a security vulnerability:

pyasn1 Vulnerable to Denial of Service via Unbounded Recursion. (CVE-2026-30922)

References:
https://www.openwall.com/lists/oss-security/2026/03/20/4
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r
https://ubuntu.com/security/notices/USN-8129-1
========================

Updated package in core/updates_testing:
========================
python3-pyasn1-0.4.8-6.2.mga9

from SRPM:
python-pyasn1-0.4.8-6.2.mga9.src.rpm

Assignee: python => qa-bugs
Status comment: Fixed upstream in 0.6.3 => (none)
Status: NEW => ASSIGNED

Comment 5 Herman Viaene 2026-04-03 16:48:58 CEST
MGA9-64 server Plasma Wayland on Compaq H000SB.
No installation issues.
Ref bug 35057, tested deluge, works OK.

Whiteboard: (none) => MGA9-64-OK
Flags: (none) => test_passed_mga9_64+
CC: (none) => herman.viaene

Comment 6 Thomas Andrews 2026-04-04 23:29:47 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2026-04-05 01:32:26 CEST

Keywords: (none) => advisory

Comment 7 Mageia Robot 2026-04-06 19:37:00 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0087.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.