UbuntuUpdates.org

Package "python3-eventlet"

Name: python3-eventlet

Description:

concurrent networking library

Latest version: 0.30.2-5ubuntu2.2
Release: jammy (22.04)
Level: security
Repository: main
Head package: python-eventlet
Homepage: https://eventlet.net

Links


Download "python3-eventlet"


Other versions of "python3-eventlet" in Jammy

Repository Area Version
base main 0.30.2-5ubuntu2
updates main 0.30.2-5ubuntu2.2

Changelog

Version: 0.30.2-5ubuntu2.2 2025-09-24 22:07:08 UTC

  python-eventlet (0.30.2-5ubuntu2.2) jammy-security; urgency=medium

  * SECURITY UPDATE: HTTP Request smuggling
    - debian/patches/CVE-2025-58068.patch: Fix request smuggling
      vulnerability by discarding trailers in eventlet/wsgi.py.
    - debian/patches/fixing_tests.py: shrinks window before connecting
      in tests/greenio_test.py. This test was causing a FTBFS (LP: #2125423).
    - CVE-2025-58068

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 15 Sep 2025 15:03:56 -0300

2125423 python-eventlet FTBFS due test failing
CVE-2025-58068 Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due



About   -   Send Feedback to @ubuntu_updates