Opened 4 months ago
Closed 3 months ago
#23492 closed enhancement (fixed)
cython-3.2.6 (Python module)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | normal | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (8)
comment:1 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 4 months ago
comment:4 by , 3 months ago
| Priority: | normal → elevated |
|---|---|
| Resolution: | fixed |
| Status: | closed → reopened |
follow-up: 7 comment:5 by , 3 months ago
| Owner: | changed from to |
|---|---|
| Status: | reopened → new |
Fixes a double-free, which is a security vulnerability, potentially leading to memory corruption and ACE. Has no CVE or GHSA from what I can tell.
comment:6 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|
comment:7 by , 3 months ago
Replying to zeckma:
Fixes a double-free, which is a security vulnerability, potentially leading to memory corruption and ACE. Has no CVE or GHSA from what I can tell.
I am not sure I agree with the fact it is a security vulnerability. From the PR it is a potential double free and it may occur "if someone else using someone else's tstring backport". That is if someone is using a code that is not in the provided cython package.
I am maybe out of my depth here, so leaving open, but I think we have enough of those security advisories to not add ones that are not deemed such by upstream.
comment:8 by , 3 months ago
| Milestone: | 98-Security → 13.1 |
|---|---|
| Priority: | elevated → normal |
| Resolution: | → fixed |
| Status: | new → closed |
I was initially debating whether we should flag it or not. I think we'll be safe by not documenting it as a security vulnerability.

3.2.6 (2026-06-24)
Bugs fixed
Other changes