Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-6075

Опубликовано: 31 окт. 2025
Источник: debian

Описание

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.2-1package
python3.13fixed3.13.11-1package
python3.13no-dsatrixiepackage
python3.11removedpackage
python3.11no-dsabookwormpackage
python3.9removedpackage
python3.9postponedbullseyepackage
pypy3unfixedpackage
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage
pypy3postponedbullseyepackage

Примечания

  • https://github.com/python/cpython/issues/136065

  • https://mail.python.org/archives/list/security-announce@python.org/thread/IUP5QJ6D4KK6ULHOMPC7DPNKRYQTQNLA/

  • https://github.com/python/cpython/commit/f029e8db626ddc6e3a3beea4eff511a71aaceb5c (main)

  • https://github.com/python/cpython/commit/631ba3407e3348ccd56ce5160c4fb2c5dc5f4d84 (v3.14.1)

  • https://github.com/python/cpython/commit/9ab89c026aa9611c4b0b67c288b8303a480fe742 (v3.13.10)

  • https://github.com/python/cpython/commit/892747b4cf0f95ba8beb51c0d0658bfaa381ebca (3.10-branch)

  • https://github.com/python/cpython/commit/2e6150adccaaf5bd95d4c19dfd04a36e0b325d8c (v3.9.25)

Связанные уязвимости

ubuntu
около 2 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

nvd
около 2 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

msrc
около 2 месяцев назад

Quadratic complexity in os.path.expandvars() with user-controlled template

github
около 2 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

suse-cvrf
3 дня назад

Security update for python36