Source: python-asteval
Version: 1.0.6-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/lmfit/asteval/pull/153
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for python-asteval.

CVE-2026-55244[0]:
| ASTEVAL is an evaluator of Python expressions and statements. Prior
| to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException,
| SystemExit, KeyboardInterrupt, and GeneratorExit to expressions
| evaluated by asteval.Interpreter.eval(), while run() and eval() in
| asteval/asteval.py catch Exception rather than these non-Exception
| BaseException subclasses. When an attacker-controlled expression
| raises one of these classes, on_raise() passes the class to
| raise_exception(), and the resulting exception bypasses the
| interpreter's safety handlers and propagates into the calling
| application. A consuming service that evaluates untrusted
| expressions can therefore be terminated or have signal and cleanup
| handling disrupted, causing denial of service. The separately
| documented read-only open() capability is not part of this
| vulnerability. This issue is fixed in version 1.0.9.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55244
    https://www.cve.org/CVERecord?id=CVE-2026-55244
[1] https://github.com/lmfit/asteval/security/advisories/GHSA-89v8-rhwq-hf77
[2] https://github.com/lmfit/asteval/pull/153

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- 
debian-science-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-science-maintainers

Reply via email to