Opened 4 months ago

Closed 3 months ago

#23492 closed enhancement (fixed)

cython-3.2.6 (Python module)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: normal Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (8)

comment:1 by pierre, 4 months ago

Owner: changed from blfs-book to pierre
Status: new → assigned

comment:2 by pierre, 4 months ago

3.2.6 (2026-06-24)

Bugs fixed

Other changes

  • Binary wheels are now built with -DNDEBUG to discard runtime assertions from CPython’s inline functions.

comment:3 by pierre, 4 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at f014b0cf152

comment:4 by zeckma, 3 months ago

Priority: normal → elevated
Resolution: fixed
Status: closed → reopened

comment:5 by zeckma, 3 months ago

Owner: changed from pierre to SecurityAdvisory
Status: reopened → new

Fixes a double-free, which is a security vulnerability, potentially leading to memory corruption and ACE. Has no CVE or GHSA from what I can tell.

comment:6 by zeckma, 3 months ago

Milestone: 13.1 → 98-Security

in reply to:  5 comment:7 by pierre, 3 months ago

Replying to zeckma:

Fixes a double-free, which is a security vulnerability, potentially leading to memory corruption and ACE. Has no CVE or GHSA from what I can tell.

I am not sure I agree with the fact it is a security vulnerability. From the PR it is a potential double free and it may occur "if someone else using someone else's tstring backport". That is if someone is using a code that is not in the provided cython package.

I am maybe out of my depth here, so leaving open, but I think we have enough of those security advisories to not add ones that are not deemed such by upstream.

comment:8 by zeckma, 3 months ago

Milestone: 98-Security → 13.1
Priority: elevated → normal
Resolution: → fixed
Status: new → closed

I was initially debating whether we should flag it or not. I think we'll be safe by not documenting it as a security vulnerability.

Note: See TracTickets for help on using tickets.