Skip to content

fix(python3.12): pin-forward to f43 for 7 CVEs#17267

Draft
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-python3.12
Draft

fix(python3.12): pin-forward to f43 for 7 CVEs#17267
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-python3.12

Conversation

@tobiasb-ms
Copy link
Copy Markdown
Contributor

CVE Pin-Forward: python3.12

Pins python3.12 to Fedora f43 HEAD (5b0b65d) to pick up
7 CVE patches added upstream.

CVEs Resolved

CVE Severity Status
CVE-2026-4519 High Tracked
CVE-2026-4786 High Tracked
CVE-2026-6100 Critical Tracked
CVE-2026-1502 Additional
CVE-2026-2297 Additional
CVE-2026-3644 Additional
CVE-2026-4224 Additional

Fedora Spec Delta

Old commit: af31abb
New commit: 5b0b65d

New patches:

  • 00478-cve-2026-4519.patch
  • 00479-cve-2026-1502.patch
  • 00480-cve-2026-4786.patch
  • 00482-cve-2026-6100.patch
  • 00483-cve-2026-2297.patch
  • 00484-cve-2026-3644.patch
  • 00485-cve-2026-4224.patch

Pin locks/python3.12.lock to Fedora f43 HEAD to pick up
CVE-specific patches added upstream.

CVEs resolved (3 tracked, 4 additional):

  Tracked:
    CVE-2026-4519 (High)
    CVE-2026-4786 (High)
    CVE-2026-6100 (Critical)

  Additional:
    CVE-2026-1502
    CVE-2026-2297
    CVE-2026-3644
    CVE-2026-4224

Fedora f43 spec delta (af31abb..5b0b65d):
  + 00478-cve-2026-4519.patch
  + 00479-cve-2026-1502.patch
  + 00480-cve-2026-4786.patch
  + 00482-cve-2026-6100.patch
  + 00483-cve-2026-2297.patch
  + 00484-cve-2026-3644.patch
  + 00485-cve-2026-4224.patch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant