Bug 1206673 (CVE-2022-40899) - VUL-0: CVE-2022-40899: python,python39,python3,python310,python36,python27,python-future: ReDos in python-future and some cpython versions
Summary: VUL-0: CVE-2022-40899: python,python39,python3,python310,python36,python27,py...
Status: RESOLVED FIXED
Alias: CVE-2022-40899
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/351670/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-40899:5.3:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2022-12-23 12:11 UTC by Cathy Hu
Modified: 2025-11-24 17:40 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Cathy Hu 2022-12-23 12:13:00 UTC
Fix: https://github.com/python/cpython/pull/17157

python-future does not have this upstream fix yet (unclear if the project is abandoned or not), but the patch should be the same as for cpython

Affected python2:
- SUSE:SLE-11-SP1:Update/python                                       2.6.9
Affected python3:
- SUSE:SLE-12:Update/python3                                          3.4.10
Affected python-future:
- SUSE:SLE-12:Update/python-future                                    0.15.2
- SUSE:SLE-12-SP2:Update/python-future                                0.15.2
- SUSE:SLE-15:Update/python-future                                    0.16.0
- SUSE:SLE-15-SP3:Update/python-future                                0.18.2
- openSUSE:Factory/python-future                                      0.18.2

Not Affected:
- SUSE:SLE-11-SP1:Update:Teradata/python27                            2.7.18
- SUSE:SLE-12-SP1:Update/python                                       2.7.18
- SUSE:SLE-12-SP4:Update/python                                       2.7.18
- SUSE:SLE-15:Update/python                                           2.7.18
- openSUSE:Factory/python                                             2.7.18
- SUSE:Carwos:1/python3                                               3.6.15
- SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36            3.6.15
- SUSE:SLE-12-SP5:Update/python36                                     3.6.15
- SUSE:SLE-15-SP3:Update/python3                                      3.6.15
- SUSE:SLE-15:Update/python3                                          3.6.15
- SUSE:SLE-15-SP3:Update/python39                                     3.9.15
- openSUSE:Factory/python39                                           3.9.16
- SUSE:SLE-15-SP4:Update/python310                                    3.10.8
- openSUSE:Factory/python310                                          3.10.9
Comment 2 OBSbugzilla Bot 2023-01-05 12:55:03 UTC
This is an autogenerated message for OBS integration:
This bug (1206673) was mentioned in
https://build.opensuse.org/request/show/1056169 Factory / python-future
Comment 6 Daniel Garcia 2023-01-09 11:24:10 UTC
I've created a Request with with a patch for each affected version of python-future and cpython.
Comment 7 Swamp Workflow Management 2023-01-12 11:23:17 UTC
SUSE-SU-2023:0076-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1206673
CVE References: CVE-2022-40899
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    python3-3.4.10-25.105.1, python3-base-3.4.10-25.105.1
SUSE Linux Enterprise Server 12-SP5 (src):    python3-3.4.10-25.105.1, python3-base-3.4.10-25.105.1
SUSE Linux Enterprise Module for Web Scripting 12 (src):    python3-3.4.10-25.105.1, python3-base-3.4.10-25.105.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2023-01-12 11:23:57 UTC
SUSE-SU-2023:0078-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1206673
CVE References: CVE-2022-40899
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Public Cloud 12 (src):    python-future-0.15.2-3.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2023-01-12 11:25:05 UTC
SUSE-SU-2023:0079-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1206673
CVE References: CVE-2022-40899
JIRA References: 
Sources used:
openSUSE Leap Micro 5.3 (src):    python-future-0.18.2-150300.3.3.1
openSUSE Leap Micro 5.2 (src):    python-future-0.18.2-150300.3.3.1
openSUSE Leap 15.4 (src):    python-future-0.18.2-150300.3.3.1
SUSE Linux Enterprise Realtime Extension 15-SP3 (src):    python-future-0.18.2-150300.3.3.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    python-future-0.18.2-150300.3.3.1
SUSE Linux Enterprise Micro 5.3 (src):    python-future-0.18.2-150300.3.3.1
SUSE Linux Enterprise Micro 5.2 (src):    python-future-0.18.2-150300.3.3.1
SUSE Linux Enterprise Micro 5.1 (src):    python-future-0.18.2-150300.3.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2023-01-12 11:25:49 UTC
SUSE-SU-2023:0080-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1206673
CVE References: CVE-2022-40899
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    python-future-0.15.2-3.5.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Maintenance Automation 2023-03-08 12:30:22 UTC
SUSE-SU-2023:0663-1: An update that solves two vulnerabilities can now be installed.

Category: security (important)
Bug References: 1206673, 1208471
CVE References: CVE-2022-40899, CVE-2023-24329
Sources used:
SUSE OpenStack Cloud 9 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE OpenStack Cloud Crowbar 9 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
Web and Scripting Module 12 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise Software Development Kit 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise Server 12 SP2 BCL 12-SP2 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise Server 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Cathy Hu 2023-09-25 12:36:35 UTC
done, closing