Debian: python3.9: fix multiple CVEs

Upgrade python3.9 to 3.9.2-1+deb11u3

To container part, following package also need be updated to adapt with
the upgraded python3.9
Upgrade python3.9-doc to 3.9.2-1+deb11u3
To ISO part, following packages need be added or updated to fix unmet
dependencies:
Upgrade libpython3.9 to 3.9.2-1+deb11u3
Upgrade libpython3.9-dev to 3.9.2-1+deb11u3
Upgrade libpython3.9-minimal to 3.9.2-1+deb11u3
Upgrade libpython3.9-stdlib to 3.9.2-1+deb11u3
Upgrade libpython3.9-dbg to 3.9.2-1+deb11u3
Upgrade python3.9-dev to 3.9.2-1+deb11u3
Upgrade python3.9-minimal to 3.9.2-1+deb11u3
Upgrade python3.9-dbg to 3.9.2-1+deb11u3

Refer to:
CVE-2022-0391: https://nvd.nist.gov/vuln/detail/CVE-2022-0391
CVE-2025-0938: https://nvd.nist.gov/vuln/detail/CVE-2025-0938
CVE-2025-1795: https://nvd.nist.gov/vuln/detail/CVE-2025-1795
https://security-tracker.debian.org/tracker/DLA-4087-1

TestPlan:
PASS: downloader; build-pkgs
PASS: build-image
PASS: install on SX-lab

Closes-Bug: 2103670

Change-Id: I1d4b1bb96d3cfca682c07e10accb057628c317ef
Signed-off-by: Peng Zhang <Peng.Zhang2@windriver.com>
This commit is contained in:
Peng Zhang 2025-03-25 16:18:02 +08:00
parent 05037ddbc3
commit b0d1bdb1e9
2 changed files with 10 additions and 8 deletions

View File

@ -615,10 +615,11 @@ libpsl5 0.21.0-1.2
libpixman-1-dev 0.40.0-1.1~deb11u1 https://snapshot.debian.org/archive/debian/20230524T024530Z/pool/main/p/pixman/libpixman-1-dev_0.40.0-1.1~deb11u1_amd64.deb
libpwquality1 1.4.4-1
libpwquality-common 1.4.4-1
libpython3.9 3.9.2-1
libpython3.9-dev 3.9.2-1
libpython3.9-minimal 3.9.2-1
libpython3.9-stdlib 3.9.2-1
libpython3.9 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/libpython3.9_3.9.2-1%2Bdeb11u3_amd64.deb
libpython3.9-dev 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/libpython3.9-dev_3.9.2-1%2Bdeb11u3_amd64.deb
libpython3.9-minimal 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/libpython3.9-minimal_3.9.2-1%2Bdeb11u3_amd64.deb
libpython3.9-stdlib 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/libpython3.9-stdlib_3.9.2-1%2Bdeb11u3_amd64.deb
libpython3.9-dbg 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/libpython3.9-dbg_3.9.2-1%2Bdeb11u3_amd64.deb
libpython3-dev 3.9.2-3
libpython3-stdlib 3.9.2-3
libquadmath0 10.2.1-6
@ -888,9 +889,10 @@ puppet-module-vswitch 13.4.0-2
pv 1.6.6-1+b1
pycadf-common 3.1.1-2
python3 3.9.2-3
python3.9 3.9.2-1
python3.9-dev 3.9.2-1
python3.9-minimal 3.9.2-1
python3.9 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/python3.9_3.9.2-1%2Bdeb11u3_amd64.deb
python3.9-dev 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/python3.9-dev_3.9.2-1%2Bdeb11u3_amd64.deb
python3.9-minimal 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/python3.9-minimal_3.9.2-1%2Bdeb11u3_amd64.deb
python3.9-dbg 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/python3.9-dbg_3.9.2-1%2Bdeb11u3_amd64.deb
python3-alabaster 0.7.8-1.1
python3-alembic 1.4.3-1
python3-amqp 5.0.3-3

View File

@ -57,7 +57,7 @@ python3-doc 3.9.2-3
python3-intelhex 2.1-2.2
python3-pybind11 2.6.2-1
python3-thriftpy 0.3.9+ds1-1+b5
python3.9-doc 3.9.2-1
python3.9-doc 3.9.2-1+deb11u3 https://snapshot.debian.org/archive/debian-security/20250320T045336Z/pool/updates/main/p/python3.9/python3.9-doc_3.9.2-1%2Bdeb11u3_all.deb
sphinx-doc 3.4.3-2
trace-cmd 2.9.1-1
tree 1.8.0-1+b1