Python, PyPy: Multiple Vulnerabilities — GLSA 202506-07

Multiple vulberabilities have been discovered in Python and PyPy, the worst of which can lead to privilege escalation.

Affected packages

dev-lang/pypy on all architectures
Affected versions < 3.10.7.3.19_p4
< 3.11.7.3.19_p9
Unaffected versions >= 3.10.7.3.19_p4
>= 3.11.7.3.19_p9
dev-lang/python on all architectures
Affected versions < 3.14.0_beta2
< 3.13.3_p1
< 3.12.10_p1
< 3.11.12_p1
< 3.10.17_p1
< 3.9.22_p1
< 3.8.20_p7
Unaffected versions >= 3.14.0_beta2
>= 3.13.3_p1
>= 3.12.10_p1
>= 3.11.12_p1
>= 3.10.17_p1
>= 3.9.22_p1
>= 3.8.20_p7

Background

Python is an interpreted, interactive, object-oriented, cross-platform programming language.

Description

Multiple vulnerabilities have been discovered in Python, PyPy3. Please review the CVE identifiers referenced below for details.

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Resolution

All Python, PyPy3 users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.14.0_beta2:3.14"
 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.13.3_p1:3.13"
 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.12.10_p1:3.12"
 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.11.12_p1:3.11"
 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.10.17_p1:3.10"
 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.9.22_p1:3.9"
 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.8.20_p7:3.8"
 # emerge --ask --oneshot --verbose ">=dev-lang/pypy-3.10.7.3.19_p4:3.10"
 # emerge --ask --oneshot --verbose ">=dev-lang/pypy-3.11.7.3.19_p9:3.11"
 

References

Release date
June 12, 2025

Latest revision
June 12, 2025: 1

Severity
high

Exploitable
local and remote

Bugzilla entries