Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42: python-asteval Critical CVE-2025-24359 Format String Threat

fedora
Calendar Grey July 18, 2025
Dist Fedora Esm H88
Mitigating CVE-2025-24359 in python-asteval for Fedora 42 will lead to enhanced system security.
Fix CVE-2025-24359 (closes rhbz#2341976)

Summary

ASTEVAL is a safe(ish) evaluator of Python expressions and statements,

using Python's ast module. The idea is to provide a simple, safe, and robust

miniature mathematical language that can handle user-input. The emphasis here

is on mathematical expressions, and so many functions from numpy are imported

and used if available.

Update Information:

Fix CVE-2025-24359 (closes rhbz#2341976)

Change Log

* Wed Jul 9 2025 Fabian Affolter - 1.0.6-1 - Update to latest upstream release (closes rhbz#2338907) - Fix CVE-2025-24359 (closes rhbz#2341976) * Tue Jun 3 2025 Python Maint - 1.0.5-3 - Rebuilt for Python 3.14

References


[ 1 ] Bug #2341976 - CVE-2025-24359 python-asteval: ASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape https://bugzilla.redhat.com/show_bug.cgi?id=2341976

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-83c141f000' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-asteval
Product: Fedora 42
Version: 1.0.6
Release: 1.fc42
Summary: Evaluator of Python expression using ast module

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here