Mailman 3 python.org
Sign In Sign Up
Manage this list Sign In Sign Up

Keyboard Shortcuts

Thread View

  • j: Next unread message
  • k: Previous unread message
  • j a: Jump to all threads
  • j l: Jump to MailingList overview

Security-SIG

Download
Threads by month
  • ----- 2026 -----
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2025 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2024 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2023 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2022 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2021 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2020 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2019 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2018 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2017 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2016 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
security-sig@python.org

April 2026

  • 2 participants
  • 2 discussions
Re: [Security-announce][CVE-2026-3298] Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
by Guido van Rossum April 21, 2026

April 21, 2026
What is {project}? --Guido On Tue, Apr 21, 2026 at 07:51 Seth Larson <seth(a)python.org> wrote: > There is a HIGH severity vulnerability affecting {project}. > > The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows > only) was missing a boundary check for the data buffer when using nbytes > parameter. This allowed for an out-of-bounds buffer write if data was > larger than the buffer size. Non-Windows platforms are not affected. > > Please see the linked CVE ID for the latest information on affected > versions: > > * https://www.cve.org/CVERecord?id=CVE-2026-3298 > * https://github.com/python/cpython/pull/148809 > _______________________________________________ > Security-announce mailing list -- security-announce(a)python.org > To unsubscribe send an email to security-announce-leave(a)python.org > https://mail.python.org/mailman3//lists/security-announce.python.org > Member address: guido(a)python.org >
1 0
0 0
Re: [Security-announce][CVE-2026-3219] pip doesn't reject concatenated ZIP and tar archives
by Wes Turner April 20, 2026

April 20, 2026
"Preventing ZIP parser confusion attacks on Python package installers" (2025-08) The Python Package Index Blog https://blog.pypi.org/posts/2025-08-07-wheel-archive-confusion-attacks/ : > What is PyPI doing to prevent ZIP confusion attacks? Is this sufficient; what else should PyPI do to prevent malformed uploads that worked before these changes? On Mon, Apr 20, 2026, 11:03 AM Seth Larson <seth(a)python.org> wrote: > There is a MEDIUM severity vulnerability affecting pip. > > pip handles concatenated tar and ZIP files as ZIP files regardless of > filename or whether a file is both a tar and ZIP file. This behavior could > result in confusing installation behavior, such as installing "incorrect" > files according to the filename of the archive. New behavior only proceeds > with installation if the file identifies uniquely as a ZIP or tar archive, > not as both. > > Please see the linked CVE ID for the latest information on affected > versions: > > * https://www.cve.org/CVERecord?id=CVE-2026-3219 > * https://github.com/pypa/pip/pull/13870 > _______________________________________________ > Security-announce mailing list -- security-announce(a)python.org > To unsubscribe send an email to security-announce-leave(a)python.org > https://mail.python.org/mailman3//lists/security-announce.python.org > Member address: wes.turner(a)gmail.com >
1 0
0 0

HyperKitty Powered by HyperKitty version 1.3.12.