unpushed

python-cryptography-42.0.5-1.fc40

FEDORA-2024-534c900eff created by cheimes 6 months ago for Fedora 40
  • Update to upstream version 42.0.5
  • Fixes CVE-2024-26130

This update has been submitted for testing by cheimes.

6 months ago

This update's test gating status has been changed to 'waiting'.

6 months ago

This update's test gating status has been changed to 'waiting'.

6 months ago

This update's test gating status has been changed to 'failed'.

6 months ago

This update has been pushed to testing.

6 months ago

Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.

6 months ago
User Icon mattf commented & provided feedback 6 months ago
karma

The following dnf problem with python3-cryptography-42.0.5-1.fc40 and python3-pyOpenSSL-23.2.0-3.fc40 prevented updating to python3-cryptography-42.0.5-1.fc40 due to a conflict with their version requirements.

 Problem: package python3-pyOpenSSL-23.2.0-3.fc40.noarch from @System requires ((python3.12dist(cryptography) < 40 or python3.12dist(cryptography) > 40) with (python3.12dist(cryptography) < 40.0.1 or python3.12dist(cryptography) > 40.0.1) with python3.12dist(cryptography) < 42~~ with python3.12dist(cryptography) >= 38), but none of the providers can be installed
   - cannot install both python3-cryptography-42.0.5-1.fc40.x86_64 from updates-testing and python3-cryptography-41.0.7-1.fc40.x86_64 from @System
   - cannot install both python3-cryptography-42.0.5-1.fc40.x86_64 from updates-testing and python3-cryptography-41.0.7-1.fc40.x86_64 from fedora
   - cannot install the best update candidate for package python3-pyOpenSSL-23.2.0-3.fc40.noarch
   - cannot install the best update candidate for package python3-cryptography-41.0.7-1.fc40.x86_64

I reported this at https://bugzilla.redhat.com/show_bug.cgi?id=2270896

User Icon cheimes commented & provided feedback 6 months ago

Let's retract this update. We need to update PyOpenSSL and investigate + fix several other packages that may have a bad upper limit.

This update has been unpushed.

User Icon geraldosimiao commented & provided feedback 6 months ago
karma

Yes, confirmed here too:

  - cannot install both python3-cryptography-42.0.5-1.fc40.x86_64 from updates-testing and python3-cryptography-41.0.7-1.fc40.x86_64 from @System
  - cannot install both python3-cryptography-42.0.5-1.fc40.x86_64 from updates-testing and python3-cryptography-41.0.7-1.fc40.x86_64 from fedora
  - não é possível instalar o melhor candidato à atualização para o pacote python3-pyOpenSSL-23.2.0-3.fc40.noarch
  - não é possível instalar o melhor candidato à atualização para o pacote python3-cryptography-41.0.7-1.fc40.x86_64

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
-3
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
6 months ago
in testing
6 months ago
BZ#2251816 python-cryptography-42.0.5 is available
0
0
BZ#2269618 CVE-2024-26130 python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override [fedora-all]
0
0

Automated Test Results