Fedora has issued an advisory on March 28: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DHEPCPZY7AYJOCFYA65AKYXVQ5H5GOMT/ Fix: https://src.fedoraproject.org/rpms/python-ply/blob/b6f74805ce8885d4c4ab1ca413d93d39dce45ed6/f/CVE-2025-56005.patch
Source RPM: (none) => python-ply-3.11-13.mga10.src.rpm, python-ply-3.11-8.mga9.src.rpmWhiteboard: (none) => MGA9TOOCVE: (none) => CVE-2025-56005Status comment: (none) => Patch available from FedoraFlags: (none) => affects_mga9+
For Cauldron, python-ply-3.11-14.mga10 solves the issue. Suggested advisory: ======================== The updated package fixes a security vulnerability: Unsafe pickle file handling in Ply. (CVE-2025-56005) References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DHEPCPZY7AYJOCFYA65AKYXVQ5H5GOMT/ ======================== Updated package in core/updates_testing: ======================== python3-ply-3.11-8.1.mga9 from SRPM: python-ply-3.11-8.1.mga9.src.rpm
Status comment: Patch available from Fedora => (none)Whiteboard: MGA9TOO => (none)Assignee: bugsquad => qa-bugsStatus: NEW => ASSIGNEDSource RPM: python-ply-3.11-13.mga10.src.rpm, python-ply-3.11-8.mga9.src.rpm => python-ply-3.11-8.mga9.src.rpmVersion: Cauldron => 9Flags: affects_mga9+ => (none)
Keywords: (none) => advisory
RH x86_64 installing python3-ply-3.11-8.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################### 1/1: python3-ply ################################################################################################### 1/1: removing python3-ply-3.11-8.mga9.noarch ################################################################################################### mageiasync requires this indirectly The application works
Whiteboard: (none) => MGA9-64-OKFlags: (none) => test_passed_mga9_64+
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0079.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED