diff --git a/patchinfo.20260306125446347687.93181000773252/_patchinfo b/patchinfo.20260306125446347687.93181000773252/_patchinfo new file mode 100644 index 0000000..3a4a3b0 --- /dev/null +++ b/patchinfo.20260306125446347687.93181000773252/_patchinfo @@ -0,0 +1,32 @@ + + VUL-0: CVE-2026-27025: python-pypdf: Possible long runtimes/large memory usage for large /ToUnicode streams + VUL-0: CVE-2025-55197: python-pypdf: Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. This requires just reading the file if a series of FlateDecode filters is used ... + + + VUL-0: CVE-2026-27628: python-pypdf: possible infinite loop when loading circular /Prev entries in cross-reference streams + VUL-0: CVE-2026-27888: python-pypdf: Manipulated FlateDecode XFA streams can exhaust RAM + + + + + VUL-0: CVE-2026-27024: python-pypdf: Possible infinite loop when processing TreeObject + VUL-0: CVE-2026-27026: python-pypdf: Possible long runtimes for malformed FlateDecode streams + mcalabkova + important + security + Security update for python-PyPDF2 + This update for python-PyPDF2 fixes the following issues: + +Changes in python-PyPDF2: + +- CVE-2026-27628: Fixed infinite loop when loading circular /Prev entries in cross-reference streams (bsc#1258940) +- CVE-2026-27888: Fixed issue where manipulated FlateDecode XFA streams can exhaust RAM (bsc#1258934) +- CVE-2025-55197: Fixed denial of service via craft PDF (bsc#1248089) +- CVE-2026-27024: Fixed infinite loop when processing TreeObject (bsc#1258691) +- CVE-2026-27025: Fixed long runtimes/large memory usage for large /ToUnicode streams (bsc#1258692) +- CVE-2026-27026: Fixed long runtimes for malformed FlateDecode streams (bsc#1258693) + +- Convert to pip-based build + + python-PyPDF2 + diff --git a/python-PyPDF2 b/python-PyPDF2 index 231b334..a694225 160000 --- a/python-PyPDF2 +++ b/python-PyPDF2 @@ -1 +1 @@ -Subproject commit 231b3346ede519ba35a7ab6f8ead4fea4c1a9376dbedc4bdaa353c162fb52688 +Subproject commit a6942256f7613a3256870b2341564627ba36c5998bce1f3dc8c366d541e87d55