Opened 6 months ago

Closed 6 months ago

#23115 closed enhancement (fixed)

pytest-9.0.3 (Python module) (Security update)

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description (last modified by Bruce Dubbs)

New point version.

CVE-2025-71176 Base Score: 6.8 MEDIUM

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Change History (6)

comment:1 by Bruce Dubbs, 6 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 6 months ago

pytest 9.0.3 (2026-04-07) Bug fixes

Fixed :func:pytest.approx which now correctly takes into account :class:~collections.abc.Mapping keys order to compare them.

Blocking a conftest.py file using the -p no: option is now explicitly disallowed. Previously this resulted in an internal assertion failure during plugin loading. Pytest now raises a clear UsageError explaining that conftest files are not plugins and cannot be disabled via -p.

Fixed crash when a test raises an exceptiongroup with tracebackhide = True.

Fixed an issue where non-string messages passed to unittest.TestCase.subTest() were not printed.

Fixed use of insecure temporary directory (CVE-2025-71176).

Improved documentation

Clarified documentation for -p vs PYTEST_PLUGINS plugin loading and fixed an incorrect -p example.

Clarified that capture fixtures (e.g. capsys and capfd) take precedence over the -s / --capture=no command-line options in :ref:Accessing captured output from a test function <accessing-captured-output>.

Clarified that the default pytest_collection hook sets session.items before it calls pytest_collection_finish, not after.

TOML integer log levels must be quoted: Updating reference documentation.

Contributor-facing changes

The test reports are now published to Codecov from GitHub Actions. The test statistics is visible on the web interface.

comment:3 by Bruce Dubbs, 6 months ago

Description: modified (diff)
Summary: pytest-9.0.3 (Python module) → pytest-9.0.3 (Python module) (Security update)

comment:4 by Bruce Dubbs, 6 months ago

Owner: changed from Bruce Dubbs to Douglas R. Reno
Status: assigned → new

Fixed at commit 98877e5ee3. Leaving open for SA.

comment:5 by Douglas R. Reno, 6 months ago

Priority: normal → elevated
Status: new → assigned

comment:6 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: assigned → closed

Additional details regarding this issue can be found at ​https://github.com/pytest-dev/pytest/issues/13669

SA-13.0-035 issued.

Note: See TracTickets for help on using tickets.