Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 42: python3.13 Important Tarfile Infinite Loop Fix CVE-2025-8194

fedora
Calendar Grey August 13, 2025
Dist Fedora Esm H88
Patch for python3.13 in Fedora 42 resolves CVE-2025-8194 infinite loop vulnerability, improving system security and reliability.
3.13.6 is the sixth maintenance release of 3.13, containing around 200 bugfixes, build improvements and documentation changes since 3.13.5

Summary

Python 3.13 is an accessible, high-level, dynamically typed, interpreted

programming language, designed with an emphasis on code readability.

It includes an extensive standard library, and has a vast ecosystem of

third-party libraries.

Update Information:

3.13.6 is the sixth maintenance release of 3.13, containing around 200 bugfixes, build improvements and documentation changes since 3.13.5. This update contains fix for https://www.cve.org/CVERecord?id=CVE-2025-8194

Change Log

* Thu Aug 7 2025 Tom\u0161 Hrn\u010diar - 3.13.5-5 - Update to 3.13.6 * Mon Jul 28 2025 Miro Hron\u010dok - 3.13.5-4 - Fix CVE-2025-8194: Tarfile infinite loop during parsing with negative member offset * Fri Jul 25 2025 Fedora Release Engineering - 3.13.5-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Wed Jun 25 2025 Karolina Surma - 3.13.5-2 - Conditionally skip tests not working with the older expat version

References


[ 1 ] Bug #2384078 - CVE-2025-8194 python3.13: Cpython infinite loop when parsing a tarfile [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2384078

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1a9ad70c05' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python3.13
Product: Fedora 42
Version: 3.13.6
Release: 1.fc42
Summary: Version 3.13 of the Python interpreter

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here