Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1188843
| From | Stefano Rivera <stefanor@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.devel.release |
| Subject | Bug#1065326: bookworm-pu: package python3.11/3.11.2-6+deb12u1 |
| Date | 2024-03-02 21:40 +0100 |
| Message-ID | <IdEjf-dZpj-1@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: python3.11@packages.debian.org, doko@debian.org Control: affects -1 + src:python3.11 User: release.debian.org@packages.debian.org Usertags: pu [ Reason ] A use-after-free causing a SEGV was found in python 3.11, affecting the the Zulip chat server. The bug is known to affect python 3.11.0 - 3.11.4. And since being fixed upstream, there have been no known related regressions. [ Impact ] Potential SEGV in python3. Known to be triggered by zulip's CI when running under coverage. [ Tests ] The Python stdlib testsuite is extensive and passes with this patch. There is a stand-alone reproducer that I've manually reproduced the bug with and verified that it's fixed. [ Risks ] The code is pretty straight-forward. It asserts that the f_frame hasn't already been freed before freeing. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable
Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#1065326: bookworm-pu: package python3.11/3.11.2-6+deb12u1 Stefano Rivera <stefanor@debian.org> - 2024-03-02 21:40 +0100 Bug#1065326: python3.11 3.11.2-6+deb12u1 flagged for acceptance Jonathan Wiltshire <jmw@debian.org> - 2024-03-03 13:20 +0100
csiph-web