pkg/60605: pkg-vulnerabilities lists already fixed python issues
"Showta Ishizaki via gnats" <[email protected]>
| Newsgroups | gmane.os.netbsd.devel.pkgsrc.bugs |
|---|---|
| Message-ID | <[email protected]> |
>Number: 60605 >Category: pkg >Synopsis: pkg-vulnerabilities lists already fixed python issues >Confidential: no >Severity: non-critical >Priority: medium >Responsible: pkg-manager >State: open >Class: doc-bug >Submitter-Id: net >Arrival-Date: Sun Aug 16 19:00:00 +0000 2026 >Originator: Showta Ishizaki >Release: NetBSD 10.1, pkg_install-20260227 >Organization: >Environment: System: NetBSD bambi.snowrabbit.org 10.1 NetBSD 10.1 (GENERIC) #0: Mon Dec 16 13:08:11 UTC 2024 [email protected]:/usr/src/sys/arch/i386/compile/GENERIC i386 Architecture: i386 Machine: i386 pkg-vulnerabilities,v 1.779 2026/08/14 21:48:05 leot Exp >Description: Thank you for keeping pkg-vulnerabilities up to date. This is a small report about a few python entries in it. Running "pkg_admin audit" on a box with python313-3.13.15 installed reports eight issues against it. Looking into them, five turned out to be fixed in CPython releases that are already out, and the installed 3.13.15 contains all five. The same five CVEs are listed for python310 through python314 with the "-[0-9]*" pattern as well, so 22 entries in all. My guess is that these were written before any release carried the fix, which was quite right at the time, and simply have not been revisited since. That is an easy thing to miss, so I have gone through them one by one below in the hope that it saves some work. For each one I took the backport commit named in the GitHub advisory, bisected the release tags of that branch to find the oldest one containing it, and then read the source at that tag and at the release before it to make sure the change really appears there and not earlier. CVE-2025-13462 -- tarfile, DIRTYPE normalisation during GNU long name handling. Fixed by gh-141707 and backported to every branch. The oldest releases carrying it are 3.10.21, 3.11.16, 3.12.14, 3.13.13 and 3.14.4. In Lib/tarfile.py the fix appears as the new "dircheck" argument to TarInfo._frombuf(). CVE-2026-2297 -- SourcelessFileLoader not going through io.open_code(). Fixed by gh-145506, backported to every branch, and released in the same five versions: 3.10.21, 3.11.16, 3.12.14, 3.13.13 and 3.14.4. In Lib/importlib/_bootstrap_external.py the loader is added to the isinstance() tuple in FileLoader.get_data(). CVE-2026-3644 -- control characters in http.cookies.Morsel. Fixed by gh-145599, again on every branch, released in 3.10.21, 3.11.16, 3.12.14, 3.13.13 and 3.14.4. A word of warning here: the obvious marker to look for, _has_control_character(), is not a reliable one, because that helper arrived with the fix for CVE-2026-0672, which this CVE completes. It is already present in the release before. I used a line the later fix adds to js_output() instead. CVE-2026-4224 -- unbounded C recursion in conv_content_model() in pyexpat. Fixed by gh-145986 on every branch, released in 3.10.21, 3.11.16, 3.12.14, 3.13.13 and 3.14.4. In Modules/pyexpat.c the fix is the _Py_EnterRecursiveCall() guard. CVE-2025-15366 -- control characters in IMAP commands. This one is narrower. Fixed by gh-143921, but backported only to 3.13 and 3.14, where it was released in 3.13.15 and 3.14.7. Lib/imaplib.py in v3.10.21, v3.11.16 and v3.12.14 still has no such check, so I have left the python310, python311 and python312 entries for it alone. The other three of the eight look right to me as they stand, and the patch does not touch them: CVE-2025-15367 -- the same treatment for poplib. The message "Control characters not allowed in commands" is in Lib/poplib.py on main only, and is absent from v3.10.21, v3.11.16, v3.12.14, v3.13.15 and v3.14.7. CVE-2025-12781 -- base64. Worth a note, because the tags are misleading here: a commit for this issue did reach the 3.13 branch, but it only added tests. The behaviour change, a DeprecationWarning in Lib/base64.py, is on main and has not been backported anywhere. CVE-2026-3479 -- pkgutil.get_data(). Upstream put the checks in and then took them out again, documenting the security model instead (gh-146121, "Clarify security model of pkgutil.getdata; revert checks"), so I do not think a fixed version will appear for this one at all. If I have misread any of this I would be glad to be told. >How-To-Repeat: On a host running python313-3.13.15: pkg_admin fetch-pkg-vulnerabilities pkg_admin audit | grep python313 Eight lines are printed, five of which are fixed in the installed version. >Fix: The diff below is against the body of pkg-vulnerabilities as published on 2026-08-16, rev 1.779. The file is clearsigned, so the signature will need regenerating; the diff covers the text only. It applies with patch(1) with no offsets and no fuzz. --- pkg-vulnerabilities.orig 2026-08-17 02:58:18 +++ pkg-vulnerabilities.new 2026-08-17 03:04:58 @@ -29478,8 +29478,8 @@ python310-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15366 python311-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15366 python312-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15366 -python313-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15366 -python314-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15366 +python313<3.13.15 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15366 +python314<3.14.7 command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15366 python310-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15367 python311-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15367 python312-[0-9]* command-injection https://nvd.nist.gov/vuln/detail/CVE-2025-15367 @@ -30181,16 +30181,16 @@ py{27,310,311,312,313,314}-tornado<6.5.5 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2026-31958 py{27,310,311,312,313,314}-wagtail<7.2.3 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2026-28222 py{27,310,311,312,313,314}-wagtail<7.2.3 cross-site-scripting https://nvd.nist.gov/vuln/detail/CVE-2026-28223 -python310-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 -python311-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 -python312-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 -python313-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 -python314-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 -python310-[0-9]* unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 -python311-[0-9]* unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 -python312-[0-9]* unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 -python313-[0-9]* unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 -python314-[0-9]* unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 +python310<3.10.21 input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 +python311<3.11.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 +python312<3.12.14 input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 +python313<3.13.13 input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 +python314<3.14.4 input-validation https://nvd.nist.gov/vuln/detail/CVE-2025-13462 +python310<3.10.21 unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 +python311<3.11.16 unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 +python312<3.12.14 unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 +python313<3.13.13 unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 +python314<3.14.4 unspecified https://nvd.nist.gov/vuln/detail/CVE-2026-2297 quickjs<20251212 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-69653 quickjs<20251212 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2025-69654 rustdesk-server-[0-9]* improper-authorization https://nvd.nist.gov/vuln/detail/CVE-2026-30784 @@ -30281,16 +30281,16 @@ python312-[0-9]* path-traversal https://nvd.nist.gov/vuln/detail/CVE-2026-3479 python313-[0-9]* path-traversal https://nvd.nist.gov/vuln/detail/CVE-2026-3479 python314-[0-9]* path-traversal https://nvd.nist.gov/vuln/detail/CVE-2026-3479 -python310-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 -python311-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 -python312-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 -python313-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 -python314-[0-9]* input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 -python310-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 -python311-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 -python312-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 -python313-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 -python314-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 +python310<3.10.21 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 +python311<3.11.16 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 +python312<3.12.14 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 +python313<3.13.13 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 +python314<3.14.4 input-validation https://nvd.nist.gov/vuln/detail/CVE-2026-3644 +python310<3.10.21 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 +python311<3.11.16 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 +python312<3.12.14 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 +python313<3.13.13 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 +python314<3.14.4 stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2026-4224 radare2<6.1.2 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2026-4174 samtools<1.21.1 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2026-31972 samtools<1.21.1 null-pointer-dereference https://nvd.nist.gov/vuln/detail/CVE-2026-31973