Pin Python3.11 package to 3.11.2-6+deb12u2 to avoid changes from CVE-2024-4032 #716
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Change from python/cpython@ba43157 has been backported by debian and released in
3.11.2-6+deb12u3
. There is not yet a PSF cpython 3.11 release that includes that change, so we cannot begin to adopt it. Until then we will have to hold this back for our base image.https://tracker.debian.org/news/1559732/accepted-python311-3112-6deb12u3-source-into-stable-security/
https://release.debian.org/proposed-updates/bookworm_diffs/python3.11_3.11.2-6+deb12u3.debdiff
https://lists.debian.org/debian-security-announce/2024/msg00172.html
https://security-tracker.debian.org/tracker/CVE-2024-4032
python/cpython#113179