Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 41: ruff Important Tracing Log Pollution Vuln 2025-5ba89a2c48

fedora
Calendar Grey September 12, 2025
Dist Fedora Esm H88
Essential patch for Fedora 41 targeting tracing log contamination in ruff-driven utilities, causing notable repercussions.
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.

Summary

An extremely fast Python linter and code formatter, written in Rust.

Ruff aims to be orders of magnitude faster than alternative tools while

integrating more functionality behind a single, common interface.

Ruff can be used to replace Flake8 (plus dozens of plugins), Black,

isort, pydocstyle, pyupgrade, autoflake, and more, all while executing

tens or hundreds of times faster than any individual tool.

Update Information:

Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.

Change Log

* Tue Sep 2 2025 Fabio Valentini - 0.11.5-7 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160 * Fri Aug 15 2025 Python Maint - 0.11.5-6 - Rebuilt for Python 3.14.0rc2 bytecode

References


[ 1 ] Bug #2391973 - CVE-2025-58160 ruff: Tracing log pollution [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2391973 [ 2 ] Bug #2392006 - CVE-2025-58160 ruff: Tracing log pollution [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392006 [ 3 ] Bug #2392045 - CVE-2025-58160 ruff: Tracing log pollution [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2392045

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5ba89a2c48' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: ruff
Product: Fedora 41
Version: 0.11.5
Release: 7.fc41
Summary: Extremely fast Python linter and code formatter

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here