extraction filters (filter="data" and filter="tar")

to be bypassed using crafted symlinks and hard links.
      CVE-2025-4517 (bsc#1244032). Also addresses CVE-2025-4435
      (gh#135034, bsc#1244061).

OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:Factory/python312?expand=0&rev=149
This commit is contained in:
2025-06-25 19:47:39 +00:00
committed by Git OBS Bridge
commit f9e1cf1836
42 changed files with 10795 additions and 0 deletions

View File

@@ -0,0 +1,16 @@
---
Lib/test/test_capi/test_mem.py | 1 +
1 file changed, 1 insertion(+)
Index: Python-3.12.2/Lib/test/test_capi/test_mem.py
===================================================================
--- Python-3.12.2.orig/Lib/test/test_capi/test_mem.py
+++ Python-3.12.2/Lib/test/test_capi/test_mem.py
@@ -110,6 +110,7 @@ class PyMemDebugTests(unittest.TestCase)
def test_pyobject_forbidden_bytes_is_freed(self):
self.check_pyobject_is_freed('check_pyobject_forbidden_bytes_is_freed')
+ @unittest.skip('Failing on Leap 15.*')
def test_pyobject_freed_is_freed(self):
self.check_pyobject_is_freed('check_pyobject_freed_is_freed')