Bug 2363676 - CVE-2025-43859 python-h11: h11 accepts some malformed Chunked-Encoding bodies [epel-10]
Summary: CVE-2025-43859 python-h11: h11 accepts some malformed Chunked-Encoding bodies...
Keywords:
Status: ON_QA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: python-h11
Version: epel10
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
Assignee: Robby Callicotte
QA Contact:
URL:
Whiteboard: {"flaws": ["c418f5c1-d1cb-4753-8088-4...
Depends On:
Blocks: CVE-2025-43859
TreeView+ depends on / blocked
 
Reported: 2025-05-02 15:40 UTC by Robby Callicotte
Modified: 2025-05-03 03:14 UTC (History)
4 users (show)

Fixed In Version:
Clone Of: 2362283
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Robby Callicotte 2025-05-02 15:40:40 UTC
+++ This bug was initially created as a clone of Bug #2362283 +++

More information about this security flaw is available in the following bug:

https://bugzilla.redhat.com/show_bug.cgi?id=2362162

Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Fedora Update System 2025-05-02 16:05:21 UTC
FEDORA-EPEL-2025-3bd90537af (python-h11-0.14.0-7.el10_0) has been submitted as an update to Fedora EPEL 10.0.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-3bd90537af

Comment 2 Fedora Update System 2025-05-02 16:06:06 UTC
FEDORA-EPEL-2025-d1e5d65673 (python-h11-0.14.0-7.el10_1) has been submitted as an update to Fedora EPEL 10.1.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-d1e5d65673

Comment 3 Fedora Update System 2025-05-03 02:26:47 UTC
FEDORA-EPEL-2025-d1e5d65673 has been pushed to the Fedora EPEL 10.1 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-d1e5d65673

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 4 Fedora Update System 2025-05-03 03:14:28 UTC
FEDORA-EPEL-2025-3bd90537af has been pushed to the Fedora EPEL 10.0 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-3bd90537af

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.


Note You need to log in before you can comment on or make changes to this bug.