Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 11: pypy3 Critical Update for DoS Issues DLA-4354-1 CVE-2024-6232

debian lts
Calendar Grey October 31, 2025
Dist Debian Esm H88
The pypy3 security update addresses critical issues in the Python library, enhancing stability and safety.
This upload fixes a few of security issues in the Python standard library included with PyPy, an alternative implementation of the Python 3 language

Summary

CVE-2024-6232

The tarfile module used to parse tar parsed header values with regular
expressions that allowed for backtracking, which could be used to cause
denial of service via specifically-crafted tar archives (ReDoS). Since
tar headers have a well-known format that doesn't require backtracking
to parse reliably, the new method of parsing only requires a single pass
over a byte stream.

CVE-2024-6923

The email module didn’t properly quote newlines when serialising
email messages, which could be used to inject newlines that would
affect the interpretation of the email headers. An attacker could
cause some email headers to be completely skipped or potentially
hide malicious headers within other headers.

CVE-2024-7592

The http.cookies, when parsing cookies that contained backslashes
for quoted characters in the cookie value, would use an algorithm
with quadratic complexity, resulting in excess CPU resources being

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: pypy3
Version: 7.3.5+dfsg-2+deb11u5
CVE ID: CVE-2024-6232 CVE-2024-6923 CVE-2024-7592 CVE-2024-11168

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here