CVE-2023-41105 not fixed in bookworm

Richard van den Berg <[email protected]> Fri, 1 Mar 2024 09:11:34 +0100
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
Dear security team,

May I ask why CVE-2023-41105 was marked as "<no-dsa> (Minor issue)"[1] ?

As the CVE description says there are plausible cases where this can 
lead to security issues.

There is a backport available for python 3.11 and it seems most other 
distros have patched this CVE.

Kind regards,

Richard van den Berg

1: https://security-tracker.debian.org/tracker/CVE-2023-41105