Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 43 python-ply Critical Unsafe Pickle Handling Fix 2026-516db080b7

fedora
Calendar Grey March 29, 2026
Dist Fedora Esm H88
Critical security fix for unsafe pickle handling in python-ply for Fedora 43. Protect your applications now!
Security fix for CVE-2025-56005

Summary

PLY is a straightforward lex/yacc implementation. Here is a list of its

essential features:

* It is implemented entirely in Python.

* It uses LR-parsing which is reasonably efficient and well suited for larger

grammars.

* PLY provides most of the standard lex/yacc features including support

for empty productions, precedence rules, error recovery, and support

for ambiguous grammars.

* PLY is straightforward to use and provides very extensive error checking.

* PLY doesn't try to do anything more or less than provide the basic lex/yacc

functionality. In other words, it's not a large parsing framework or a

component of some larger system.

Update Information:

Security fix for CVE-2025-56005

Change Log

* Wed Mar 25 2026 Charalampos Stratakis - 3.11-33 - Security fix for CVE-2025-56005 - Fixes: rhbz#2437981 * Sat Jan 17 2026 Fedora Release Engineering - 3.11-32 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Thu Dec 18 2025 Tom Callaway - 3.11-31 - fix build for Python 3.15 - use modern macros

References


[ 1 ] Bug #2437981 - CVE-2025-56005 python-ply: Unsafe pickle file handling in Ply [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2437981

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-516db080b7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-ply
Product: Fedora 43
Version: 3.11
Release: 33.fc43
Summary: Python Lex-Yacc

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here