stable

python3.9-3.9.21-1.fc41

FEDORA-2024-47e4624c89 created by churchyard a month ago for Fedora 41

Python 3.9.21 security release.

Security content in this release

  • gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and is_unspecified.
  • CVE-2024-9287: gh-124651: Properly quote template strings in venv activation scripts.
  • gh-103848: Added checks to ensure that [ bracketed ] hosts found by urllib.parse.urlsplit() are of IPv6 or IPvFuture format.
  • gh-95588: Clarified the conflicting advice given in the ast documentation about ast.literal_eval() being "safe" for use on untrusted input while at the same time warning that it can crash the process. The latter statement is true and is deemed unfixable without a large amount of work unsuitable for a bugfix. So we keep the warning and no longer claim that literal_eval is safe.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2024-47e4624c89

This update has been submitted for testing by churchyard.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update has been pushed to testing.

a month ago

This update has been submitted for stable by bodhi.

a month ago

This update has been pushed to stable.

a month ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-2
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago
BZ#2321662 CVE-2024-9287 python3.9: Virtual environment (venv) activation scripts don't quote paths [fedora-all]
0
0

Automated Test Results