Skip to content

pypy advisories #13568

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Mar 3, 2025
Merged

pypy advisories #13568

merged 3 commits into from
Mar 3, 2025

Conversation

utieyin
Copy link
Contributor

@utieyin utieyin commented Mar 3, 2025

Adding false positive determinations for CVE-2022-37454 in pypy 3.10 and pypy 3.11 buffer overflow vulnerability in _sha3 module

@mamccorm mamccorm requested a review from a team March 3, 2025 14:32
@powersj powersj requested review from kbsteere and removed request for a team March 3, 2025 14:52
@powersj
Copy link
Member

powersj commented Mar 3, 2025

@kbsteere assigning directly to you for review. Please verify the reason and respond. Thanks!

@utieyin
Copy link
Contributor Author

utieyin commented Mar 3, 2025

This might be helpful as well python/cpython#98517 (comment)

…ity in _sha3 module for PyPy 3.10 and 3.11 with detailed patch references and mitigation notes
@utieyin utieyin dismissed kbsteere’s stale review March 3, 2025 20:23

Applied suggested changes

@powersj powersj requested a review from kbsteere March 3, 2025 20:30
@kbsteere kbsteere enabled auto-merge March 3, 2025 20:47
@kbsteere kbsteere disabled auto-merge March 3, 2025 20:47
@kbsteere kbsteere enabled auto-merge March 3, 2025 20:47
@kbsteere kbsteere added this pull request to the merge queue Mar 3, 2025
@kbsteere kbsteere removed this pull request from the merge queue due to a manual request Mar 3, 2025
@kbsteere kbsteere added this pull request to the merge queue Mar 3, 2025
Merged via the queue into wolfi-dev:main with commit 790c136 Mar 3, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants