Re: [LFS Trac] #5961: Python security fixes: CVE-2026-12003,11940,0864,11972 (was: Python security fixes: CVE-2026-12003,11940,0864)

LFS Trac ([email protected] via lfs-book Mailing List) <[email protected]> Wed, 24 Jun 2026 20:28:05 -0000
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5961: Python security fixes: CVE-2026-12003,11940,0864,11972
-------------------------+-----------------------
 Reporter:  Joe Locash   |       Owner:  lfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-----------------------
Changes (by Joe Locash):

 * summary:  Python security fixes: CVE-2026-12003,11940,0864 => Python
     security fixes: CVE-2026-12003,11940,0864,11972

Comment:

 {{{
 There is a MEDIUM severity vulnerability affecting CPython.

 When using the "tarfile" module with a file opened in "streaming mode"
 (mode="r|") the tarfile module did not properly handle EOF, meaning an
 archive could be parsed in an infinite loop.

 Please see the linked CVE ID for the latest information on affected
 versions:

 * https://www.cve.org/CVERecord?id=CVE-2026-11972
 * https://github.com/python/cpython/pull/151982
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5961#comment:2>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page