Re: [LFS Trac] #5907: python3-3.14.4
| Newsgroups | gmane.linux.lfs.book |
|---|---|
| Message-ID | <[email protected]> |
#5907: python3-3.14.4
-------------------------+-------------------------------
Reporter: Bruce Dubbs | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: Book | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-------------------------------
Comment (by Douglas R. Reno):
An additional CVE was fixed in this release - CVE-2026-3446. That follows
https://github.com/python/cpython/pull/145267, the advisory from upstream
is:
{{{
When calling base64.b64decode() or related functions the decoding process
would stop
after encountering the first padded quad regardless of whether there was
more
information to be processed. This can lead to data being accepted which
may be processed
differently by other implementations. Use "strict=True" to enable stricter
processing of
base64 data.
Please see the linked CVE ID for the latest information on affected
versions:
* https://www.cve.org/CVERecord?id=CVE-2026-3446
* https://github.com/python/cpython/pull/145267
}}}
This one was rated as Medium
--
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5907#comment:6>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.
--
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page