Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 11 Python3.9 Advisory DLA-4583-1 Multiple Issues Found

debian lts
Calendar Grey May 15, 2026
Dist Debian Esm H88
Multiple vulnerabilities found in Debian's Python 3.9 could compromise security; apply updates urgently to mitigate risks.
Multiple vulnerabilities were discovered in Python 3.9

Summary

CVE-2025-13462

The "tarfile" module would still apply normalization of AREGTYPE
(\x00) blocks to DIRTYPE, even while processing a multi-block member
such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a
crafted tar archive being misinterpreted by the tarfile module
compared to other implementations.

CVE-2026-0672

When using http.cookies.Morsel, user-controlled cookie values and
parameters can allow injecting HTTP headers into messages. Patch
rejects all control characters within cookie names, values, and
parameters.

CVE-2026-2297

The import hook in CPython that handles legacy *.pyc files
(SourcelessFileLoader) is incorrectly handled in FileLoader (a base
class) and so does not use io.open_code() to read the .pyc files.
sys.audit handlers for this audit event therefore do not fire.

CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in
http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator,

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: python3.9
Version: 3.9.2-1+deb11u7
CVE ID: CVE-2025-13462 CVE-2026-0672 CVE-2026-2297 CVE-2026-3644
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here