Bug 35294 - python-ply new security issue CVE-2025-56005
Summary: python-ply new security issue CVE-2025-56005
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-03-30 15:33 CEST by Nicolas Salguero
Modified: 2026-04-01 01:08 CEST (History)
2 users (show)

See Also:
Source RPM: python-ply-3.11-8.mga9.src.rpm
CVE: CVE-2025-56005
Status comment:
j.alberto.vc: test_passed_mga9_64+


Attachments

Nicolas Salguero 2026-03-30 15:36:03 CEST

Source RPM: (none) => python-ply-3.11-13.mga10.src.rpm, python-ply-3.11-8.mga9.src.rpm
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2025-56005
Status comment: (none) => Patch available from Fedora
Flags: (none) => affects_mga9+

Comment 1 Nicolas Salguero 2026-03-30 16:07:30 CEST
For Cauldron, python-ply-3.11-14.mga10 solves the issue.


Suggested advisory:
========================

The updated package fixes a security vulnerability:

Unsafe pickle file handling in Ply. (CVE-2025-56005)

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DHEPCPZY7AYJOCFYA65AKYXVQ5H5GOMT/
========================

Updated package in core/updates_testing:
========================
python3-ply-3.11-8.1.mga9

from SRPM:
python-ply-3.11-8.1.mga9.src.rpm

Status comment: Patch available from Fedora => (none)
Whiteboard: MGA9TOO => (none)
Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED
Source RPM: python-ply-3.11-13.mga10.src.rpm, python-ply-3.11-8.mga9.src.rpm => python-ply-3.11-8.mga9.src.rpm
Version: Cauldron => 9
Flags: affects_mga9+ => (none)

katnatek 2026-03-31 02:53:44 CEST

Keywords: (none) => advisory

Comment 2 katnatek 2026-03-31 04:02:46 CEST
RH x86_64

installing python3-ply-3.11-8.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ###################################################################################################
      1/1: python3-ply           ###################################################################################################
      1/1: removing python3-ply-3.11-8.mga9.noarch
                                 ###################################################################################################

mageiasync requires this indirectly

The application works

Whiteboard: (none) => MGA9-64-OK
Flags: (none) => test_passed_mga9_64+

Comment 3 Thomas Andrews 2026-03-31 18:30:00 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 4 Mageia Robot 2026-04-01 01:08:29 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0079.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.