Alerts This Week
Warning Icon 1 1,146
Alerts This Week
Warning Icon 1 1,146

Fedora 42 python-cbor2 Critical Integer Underflow DoS 2026-0afc953516

fedora
Calendar Grey April 22, 2026
Dist Fedora Esm H88
Backport patch for CVE-2025-64076 in python-cbor2 of Fedora 42 to prevent integer underflow and DoS.
Backport upstream patch for CVE-2025-64076

Summary

This library provides encoding and decoding for the Concise Binary Object

Representation (CBOR) (RFC 7049) serialization format.

Update Information:

Backport upstream patch for CVE-2025-64076

Change Log

* Fri Apr 10 2026 Carl George - 5.6.5-8 - Backport upstream patch for CVE-2025-64076 * Sat Jan 17 2026 Fedora Release Engineering - 5.6.5-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Sep 19 2025 Python Maint - 5.6.5-6 - Rebuilt for Python 3.14.0rc3 bytecode * Fri Aug 15 2025 Python Maint - 5.6.5-5 - Rebuilt for Python 3.14.0rc2 bytecode * Fri Jul 25 2025 Fedora Release Engineering - 5.6.5-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Tue Jun 3 2025 Python Maint - 5.6.5-3 - Rebuilt for Python 3.14

References


[ 1 ] Bug #2418105 - CVE-2025-64076 python-cbor2: cbor2: Integer Underflow and Memory Leak leading to Denial of Service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418105

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0afc953516' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-cbor2
Product: Fedora 42
Version: 5.6.5
Release: 8.fc42
Summary: Python CBOR (de)serializer with extensive tag support

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here