Fix jit backend for ppc64le and s390x. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6c4a7cd1b1 2026-03-29 00:48:39.566734+00:00 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 43 Version : 7.3.21 Release : 3.fc43 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Fix jit backend for ppc64le and s390x -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 19 2026 Charalampos Stratakis - 7.3.21-2 - Security fix for CVE-2025-56005 for the bundled ply within the bundled pycparser - Fixes: rhbz#2431976 * Thu Mar 19 2026 Charalampos Stratakis - 7.3.21-1 - Update to 7.3.21 - Fixes: rhbz#2447284 * Thu Mar 12 2026 Miro Hron\u010dok - 7.3.20-12 - Rebuilt for improvements of %python_wheel_inject_sbom in python-rpm- macros-3.14-11 * Fri Jan 30 2026 Miroslav Such - 7.3.20-11 - migrate license to SPDX * Sat Jan 17 2026 Fedora Release Engineering - 7.3.20-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Jan 7 2026 Miro Hron\u010dok - 7.3.20-9 - Enable JIT on riscv64 * Wed Sep 24 2025 Miro Hron\u010dok - 7.3.20-6 - Inject SBOM into the installed wheels -------------------------------------------------------------------------------- References: [ 1 ] Bug #2431976 - CVE-2025-56005 pypy: From CVEorg collector [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2431976 [ 2 ] Bug #2447284 - pypy-7.3.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447284 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6c4a7cd1b1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 43 pypy fixes jit backend and addresses critical security issue, enhancing Python compatibility.. Fedora 43 pypy update important security fix network threats. . Severity: Important. LinuxSecurity.com Team
Fix jit backend for ppc64le and s390x. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-496bf1e0dd 2026-03-29 00:15:07.927106+00:00 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 44 Version : 7.3.21 Release : 3.fc44 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Fix jit backend for ppc64le and s390x -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 19 2026 Charalampos Stratakis - 7.3.21-2 - Security fix for CVE-2025-56005 for the bundled ply within the bundled pycparser - Fixes: rhbz#2431976 * Thu Mar 19 2026 Charalampos Stratakis - 7.3.21-1 - Update to 7.3.21 - Fixes: rhbz#2447284 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2431976 - CVE-2025-56005 pypy: From CVEorg collector [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2431976 [ 2 ] Bug #2447284 - pypy-7.3.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447284 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-496bf1e0dd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys usedby the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a37bf9ddbd 2025-07-20 00:46:18.199989+00:00 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 42 Version : 7.3.20 Release : 2.fc42 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Update to 7.3.20 Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 (in pip and setuptools wheels) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 10 2025 Charalampos Stratakis - 7.3.20-1 - Update to 7.3.20 - Fixes: rhbz#2376234 * Thu Jul 10 2025 Charalampos Stratakis - 7.3.19-2 - Security fixes for CVE-2025-47273, CVE-2024-47081 and CVE-2025-50181 - Fixes: rhbz#2367430, rhbz#2372476, rhbz#2373817 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2367430 - CVE-2025-47273 pypy: Path Traversal Vulnerability in setuptools PackageIndex [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2367430 [ 2 ] Bug #2372476 - CVE-2024-47081 pypy: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2372476 [ 3 ] Bug #2373817 - CVE-2025-50181 pypy: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2373817 [ 4 ] Bug #2376234 - pypy-7.3.20 is available https://bugzilla.redhat.com/show_bug.cgi?id=2376234 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a37bf9ddbd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Multiple vulberabilities have been discovered in Python and PyPy, the worst of which can lead to privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202506-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Python, PyPy: Multiple Vulnerabilities Date: June 12, 2025 Bugs: #929045, #937124, #938432, #939206, #945845, #953493, #956682, #957088 ID: 202506-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulberabilities have been discovered in Python and PyPy, the worst of which can lead to privilege escalation. Background ========== Python is an interpreted, interactive, object-oriented, cross-platform programming language. Affected packages ================= Package Vulnerable Unaffected --------------- --------------------- ---------------------- dev-lang/pypy < 3.10.7.3.19_p4:3.10 > = 3.10.7.3.19_p4:3.10 < 3.11.7.3.19_p9:3.11 > = 3.11.7.3.19_p9:3.11 dev-lang/python < 3.10.17_p1:3.10 > = 3.10.17_p1:3.10 < 3.11.12_p1:3.11 > = 3.11.12_p1:3.11 < 3.12.10_p1:3.12 > = 3.12.10_p1:3.12 < 3.13.3_p1:3.13 > = 3.13.3_p1:3.13 < 3.14.0_beta2:3.14 > = 3.14.0_beta2:3.14 < 3.8.20_p7:3.8 > = 3.8.20_p7:3.8 < 3.9.22_p1:3.9 > = 3.9.22_p1:3.9 Description =========== Multiple vulnerabilities have been discovered in Python, PyPy3. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Python, PyPy3 usersshould upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/python-3.14.0_beta2:3.14" # emerge --ask --oneshot --verbose "> =dev-lang/python-3.13.3_p1:3.13" # emerge --ask --oneshot --verbose "> =dev-lang/python-3.12.10_p1:3.12" # emerge --ask --oneshot --verbose "> =dev-lang/python-3.11.12_p1:3.11" # emerge --ask --oneshot --verbose "> =dev-lang/python-3.10.17_p1:3.10" # emerge --ask --oneshot --verbose "> =dev-lang/python-3.9.22_p1:3.9" # emerge --ask --oneshot --verbose "> =dev-lang/python-3.8.20_p7:3.8" # emerge --ask --oneshot --verbose "> =dev-lang/pypy-3.10.7.3.19_p4:3.10" # emerge --ask --oneshot --verbose "> =dev-lang/pypy-3.11.7.3.19_p9:3.11" References ========== [ 1 ] CVE-2024-6232 https://nvd.nist.gov/vuln/detail/CVE-2024-6232 [ 2 ] CVE-2024-6923 https://nvd.nist.gov/vuln/detail/CVE-2024-6923 [ 3 ] CVE-2024-7592 https://nvd.nist.gov/vuln/detail/CVE-2024-7592 [ 4 ] CVE-2024-8088 https://nvd.nist.gov/vuln/detail/CVE-2024-8088 [ 5 ] CVE-2024-12718 https://nvd.nist.gov/vuln/detail/CVE-2024-12718 [ 6 ] CVE-2025-4138 https://nvd.nist.gov/vuln/detail/CVE-2025-4138 [ 7 ] CVE-2025-4330 https://nvd.nist.gov/vuln/detail/CVE-2025-4330 [ 8 ] CVE-2025-4516 https://nvd.nist.gov/vuln/detail/CVE-2025-4516 [ 9 ] CVE-2025-4517 https://nvd.nist.gov/vuln/detail/CVE-2025-4517 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202506-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been discovered in pypy and pypy3, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202409-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: pypy, pypy3: Multiple Vulnerabilities Date: September 22, 2024 Bugs: #741496, #741560, #774114, #782520 ID: 202409-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in pypy and pypy3, the worst of which could lead to arbitrary code execution. Background ========== A fast, compliant alternative implementation of the Python language. Affected packages ================= Package Vulnerable Unaffected ----------------------- ----------------- ------------------ dev-python/pypy < 7.3.3_p37_p1-r1 > = 7.3.3_p37_p1-r1 dev-python/pypy-exe < 7.3.2 > = 7.3.2 dev-python/pypy-exe-bin < 7.3.2 Vulnerable! dev-python/pypy3 < 7.3.3_p37_p1-r1 > = 7.3.3_p37_p1-r1 Description =========== Multiple vulnerabilities have been discovered in pypy. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All pypy users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/pypy-7.3.3_p37_p1-r1" # emerge --ask --oneshot --verbose "> =dev-python/pypy-exe-7.3.2" # emerge --ask --oneshot --verbose "> =dev-python/pypy-exe-bin-7.3.2" All pypy3 users should upgrade to the latest version: # emerge --sync # emerge --ask--oneshot --verbose "> =dev-python/pypy3-7.3.3_p37_p1-r1" References ========== [ 1 ] CVE-2020-27619 https://nvd.nist.gov/vuln/detail/CVE-2020-27619 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202409-12 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Security fix for CVE-2023-5752 (in the bundled pip).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-797928fed3 2024-05-10 01:33:48.476520 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 38 Version : 7.3.15 Release : 3.fc38 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-5752 (in the bundled pip). -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Charalampos Stratakis - 7.3.15-3 - Security fix for CVE-2023-5752 for the bundled pip wheel - Resolves: rhbz#2250771 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250765 - CVE-2023-5752 pip: Mercurial configuration injectable in repo revision when installing via pip https://bugzilla.redhat.com/show_bug.cgi?id=2250765 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-797928fed3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for CVE-2023-5752 (in the bundled pip).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-dada06a500 2024-05-10 01:04:28.477496 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 39 Version : 7.3.15 Release : 3.fc39 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-5752 (in the bundled pip). -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Charalampos Stratakis - 7.3.15-3 - Security fix for CVE-2023-5752 for the bundled pip wheel - Resolves: rhbz#2250771 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250765 - CVE-2023-5752 pip: Mercurial configuration injectable in repo revision when installing via pip https://bugzilla.redhat.com/show_bug.cgi?id=2250765 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-dada06a500' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for CVE-2023-5752 (in the bundled pip).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-612986fdfa 2024-05-09 01:38:47.479807 -------------------------------------------------------------------------------- Name : pypy Product : Fedora 40 Version : 7.3.15 Release : 3.fc40 URL : https://pypy.org/ Summary : Python implementation with a Just-In-Time compiler Description : PyPy's implementation of Python, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc) This build of PyPy has JIT-compilation enabled. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-5752 (in the bundled pip). -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 30 2024 Charalampos Stratakis - 7.3.15-3 - Security fix for CVE-2023-5752 for the bundled pip wheel - Resolves: rhbz#2250771 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2250765 - CVE-2023-5752 pip: Mercurial configuration injectable in repo revision when installing via pip https://bugzilla.redhat.com/show_bug.cgi?id=2250765 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-612986fdfa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.