Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Fedora 42: PyPy Critical Security Fix CVE-2025-47273, 2025-a37bf9ddbd

fedora
Calendar Grey July 20, 2025
Scroller Fedora
Critical security patch released for PyPy in Fedora 42 addressing several vulnerabilities concerning pip and setuptools functionalities.
Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels)

Summary

PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU

architectures, and various optimized implementations of the standard types

(strings, dictionaries, etc)

This build of PyPy has JIT-compilation enabled.

Update Information:

Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels)

Change Log

* Thu Jul 10 2025 Charalampos Stratakis - 7.3.20-1 - Update to 7.3.20 - Fixes: rhbz#2376234 * Thu Jul 10 2025 Charalampos Stratakis - 7.3.19-2 - Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 - Fixes: rhbz#2367430, rhbz#2372476, rhbz#2373817

References


[ 1 ] Bug #2367430 - CVE-2025-47273 pypy: Path Traversal Vulnerability in setuptools PackageIndex [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2367430 [ 2 ] Bug #2372476 - CVE-2024-47081 pypy: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2372476 [ 3 ] Bug #2373817 - CVE-2025-50181 pypy: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2373817 [ 4 ] Bug #2376234 - pypy-7.3.20 is available https://bugzilla.redhat.com/show_bug.cgi?id=2376234

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a37bf9ddbd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pypy
Product: Fedora 42
Version: 7.3.20
Release: 2.fc42
Summary: Python implementation with a Just-In-Time compiler

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.