[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-06-01 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #15 from [email protected] ---
A commit in branch 2025Q2 references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=48ce6bb010ea3f6cd69865939b7e30191369c771

commit 48ce6bb010ea3f6cd69865939b7e30191369c771
Author: Charlie Li 
AuthorDate: 2025-05-29 20:21:11 +
Commit: Charlie Li 
CommitDate: 2025-06-01 18:22:14 +

lang/python39: pull in upstream commit addressing CVE-2025-4516

Reference: https://github.com/python/cpython/pull/134346

PR: 287009
(cherry picked from commit c9ca6e615dfedfe9b2a4d3a3f1f6e7c39a84747c)

 lang/python39/Makefile | 4 
 lang/python39/distinfo | 4 +++-
 2 files changed, 7 insertions(+), 1 deletion(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-06-01 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #13 from [email protected] ---
A commit in branch 2025Q2 references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=7a1a2f8f2e3d6a41ebd7120f14c31e6a2dfba809

commit 7a1a2f8f2e3d6a41ebd7120f14c31e6a2dfba809
Author: Charlie Li 
AuthorDate: 2025-05-29 04:36:01 +
Commit: Charlie Li 
CommitDate: 2025-06-01 18:24:17 +

lang/python311: pull in upstream commit addressing CVE-2025-4516

Reference: https://github.com/python/cpython/pull/134341

PR: 287009
(cherry picked from commit 5e57ff8453ec6c1172fc575274cb5c466dd0bd30)

 lang/python311/Makefile | 4 
 lang/python311/distinfo | 4 +++-
 2 files changed, 7 insertions(+), 1 deletion(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-06-01 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #14 from [email protected] ---
A commit in branch 2025Q2 references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=1c76486b06cd2b8a439af96f1dc0e9335afcda64

commit 1c76486b06cd2b8a439af96f1dc0e9335afcda64
Author: Charlie Li 
AuthorDate: 2025-05-29 15:59:50 +
Commit: Charlie Li 
CommitDate: 2025-06-01 18:19:39 +

lang/python310: pull in upstream commit addressing CVE-2025-4516

Reference: https://github.com/python/cpython/pull/134345

PR: 287009
(cherry picked from commit f52105e7061d6da4a25cc3fb1d07048093bc03ef)

 lang/python310/Makefile | 4 
 lang/python310/distinfo | 4 +++-
 2 files changed, 7 insertions(+), 1 deletion(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-29 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

Charlie Li  changed:

   What|Removed |Added

 Resolution|--- |FIXED
 Status|In Progress |Closed

--- Comment #12 from Charlie Li  ---
These will land in quarterly in due time.

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-29 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #11 from [email protected] ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=c9ca6e615dfedfe9b2a4d3a3f1f6e7c39a84747c

commit c9ca6e615dfedfe9b2a4d3a3f1f6e7c39a84747c
Author: Charlie Li 
AuthorDate: 2025-05-29 20:21:11 +
Commit: Charlie Li 
CommitDate: 2025-05-29 20:21:11 +

lang/python39: pull in upstream commit addressing CVE-2025-4516

Reference: https://github.com/python/cpython/pull/134346

PR: 287009

 lang/python39/Makefile | 4 
 lang/python39/distinfo | 4 +++-
 2 files changed, 7 insertions(+), 1 deletion(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-29 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #10 from George Mitchell  ---
Thank you; now able to upgrade lang/python311!

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-29 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #9 from [email protected] ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=f52105e7061d6da4a25cc3fb1d07048093bc03ef

commit f52105e7061d6da4a25cc3fb1d07048093bc03ef
Author: Charlie Li 
AuthorDate: 2025-05-29 15:59:50 +
Commit: Charlie Li 
CommitDate: 2025-05-29 15:59:50 +

lang/python310: pull in upstream commit addressing CVE-2025-4516

Reference: https://github.com/python/cpython/pull/134345

PR: 287009

 lang/python310/Makefile | 4 
 lang/python310/distinfo | 4 +++-
 2 files changed, 7 insertions(+), 1 deletion(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-28 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #8 from [email protected] ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=5e57ff8453ec6c1172fc575274cb5c466dd0bd30

commit 5e57ff8453ec6c1172fc575274cb5c466dd0bd30
Author: Charlie Li 
AuthorDate: 2025-05-29 04:36:01 +
Commit: Charlie Li 
CommitDate: 2025-05-29 04:38:19 +

lang/python311: pull in upstream commit addressing CVE-2025-4516

Reference: https://github.com/python/cpython/pull/134341

PR: 287009

 lang/python311/Makefile | 4 
 lang/python311/distinfo | 4 +++-
 2 files changed, 7 insertions(+), 1 deletion(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-28 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

Charlie Li  changed:

   What|Removed |Added

 CC||[email protected]

--- Comment #7 from Charlie Li  ---
*** Bug 287121 has been marked as a duplicate of this bug. ***

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-27 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #6 from Charlie Li  ---
Out of those we have in our tree, only the 3.12 commit has been merged
upstream. I will include the 3.13 commit in review D49680/bug 274671.

Outstanding upstream pull requests (that will need manual verification before
committing here):
- 3.9: https://github.com/python/cpython/pull/134346
- 3.10: https://github.com/python/cpython/pull/134345
- 3.11: https://github.com/python/cpython/pull/134341

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-27 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #4 from [email protected] ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=feea6ed68da6b27056b310788684aad7ac36f2c0

commit feea6ed68da6b27056b310788684aad7ac36f2c0
Author: Charlie Li 
AuthorDate: 2025-05-27 19:24:47 +
Commit: Charlie Li 
CommitDate: 2025-05-27 19:27:36 +

lang/python312: pull in upstream commit addressing CVE-2025-4516

Reference: https://github.com/python/cpython/pull/134337

PR: 287009

 lang/python312/Makefile | 4 
 lang/python312/distinfo | 4 +++-
 2 files changed, 7 insertions(+), 1 deletion(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-27 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #5 from [email protected] ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=692ef6d1cf789c5aa76c1a01ed4c83ac7e2dac37

commit 692ef6d1cf789c5aa76c1a01ed4c83ac7e2dac37
Author: Charlie Li 
AuthorDate: 2025-05-27 19:17:09 +
Commit: Charlie Li 
CommitDate: 2025-05-27 19:27:35 +

security/vuxml: adjust lang/python3 versions for CVE-2025-4516

PORTREVISIONs are bumped for each port containing the respective
upstream commit that is not included in any release yet.

PR: 287009

 security/vuxml/vuln/2025.xml | 8 
 1 file changed, 4 insertions(+), 4 deletions(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-27 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

Charlie Li  changed:

   What|Removed |Added

 Status|Open|In Progress
 CC||[email protected]

--- Comment #3 from Charlie Li  ---
Given that upstream backport pull requests for each individual branch
(auto-backport failed) have been opened and merged, I will add the appropriate
commits as PATCHFILES.

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-24 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

Fernando Apesteguía  changed:

   What|Removed |Added

 Status|New |Open
 CC||[email protected]

--- Comment #2 from Fernando Apesteguía  ---
I suppose that commit can be easily added with

EXTRA_SITE and EXTRA_PATCHES, but I will leave that to the python@ team.

Thanks for the heads up!

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-24 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

--- Comment #1 from [email protected] ---
A commit in branch main references this bug:

URL:
https://cgit.FreeBSD.org/ports/commit/?id=5e6a4ea2aa12abbf7eab30a7d7b37cfda49000d3

commit 5e6a4ea2aa12abbf7eab30a7d7b37cfda49000d3
Author: Fernando Apesteguía 
AuthorDate: 2025-05-24 15:20:34 +
Commit: Fernando Apesteguía 
CommitDate: 2025-05-24 15:33:50 +

security/vuxml: Add python3 vulnerability

 * CVE-2025-4516

PR: 287009
Reported by:ngie@

 security/vuxml/vuln/2025.xml | 44 
 1 file changed, 44 insertions(+)

-- 
You are receiving this mail because:
You are the assignee for the bug.


[Bug 287009] lang/python3*: CVE-2025-4516 (use-after-free issue with unicode-escape decoder related to error= handling)

2025-05-22 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=287009

Enji Cooper  changed:

   What|Removed |Added

   Assignee|[email protected]  |[email protected]

-- 
You are receiving this mail because:
You are the assignee for the bug.