Re: [BLFS Trac] #23492: cython-3.2.6 (Python module)
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23492: cython-3.2.6 (Python module)
-------------------------+-------------------------------
Reporter: Bruce Dubbs | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: elevated | Milestone: 98-Security
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-------------------------------
Comment (by pierre):
Replying to [comment:5 zeckma]:
> Fixes a double-free, which is a security vulnerability, potentially
leading to memory corruption and ACE. Has no CVE or GHSA from what I can
tell.
I am not sure I agree with the fact it is a security vulnerability. From
the PR it is a '''potential''' double free and it may occur "if someone
else using someone else's tstring backport". That is if someone is using a
code that is not in the provided cython package.
I am maybe out of my depth here, so leaving open, but I think we have
enough of those security advisories to not add ones that are not deemed
such by upstream.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23492#comment:7>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page