From nobody Wed Sep 09 21:08:57 2026 X-Original-To: python@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hgD220rXCz6rPwL for ; Wed, 09 Sep 2026 21:08:58 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hgD220BTcz3RBg for ; Wed, 09 Sep 2026 21:08:58 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788988138; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/QJB74ClnFP7cL+nIMxYWwsdOSQr5C+n4t83ssP8o0E=; b=xJlHRCe4QGkcnOM6PsZjuVlbdxkvf3LbEVESttz2qt2n7qaL9Zw6hw5knOnOWfGAwMpD5x 0l8dXWiJPOiyfGV47FQ2oClvj7lM/yp0PPc2miR0mopld6VbUx+oHVNcuurYD3tNhq6Nrv bhV8dngrncB7URiMkYnGKZgWxGOMk6wvRyrb1eXf1QsuZ2sUZsCiKn7LK/nSRKc7sdAxfE iqum+qOOoJcB+eF3xL6VK6doH/Y2o43YH23BraU0NgHhTciqOmckqUqWbxRxJZ047AG2p4 NtkdiInE5ma4oB2a4eam0PttLGu8gpOmMSbquSpYf1b8thG47/6K4yfMfkA59Q== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1788988138; b=TNAPo/0cJ0PJ3z1bkn5P271s26s9u1eCrum0ItPbkXfuGx4JzL4CgpTrdQY1ILfkpXnuQh GqblMLgSsHzjxmTR3zzhdOw0M+nIqFzaUk9/HgrGzyHx1xGM6K/W51QqlhA5ZtAZI7h2Zf dOPVM/JLC3otM3/g6rZ++IzxC3ErBK3/5qLuBHEQsBqK9GaxWxv3tLD++lDp2PvMNQmOTF lJxtVkDjoKHGcytLGbP4Z5jfLdf5eblmoi6+1rlGuWIetQzu2D6Y9VBWc/G3lhM61mI52W vhtl61MvbxxKWvxuDsVU70XFL3R1CwQuVvrDwq4x2DEe3UgBngrQzVyK1Lpmeg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788988138; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/QJB74ClnFP7cL+nIMxYWwsdOSQr5C+n4t83ssP8o0E=; b=R+XXzBJYiFlzv04JVN1zKKabZ41WHNZt/IrSu+cMfdKHvcOnnbJgw+HPp4bB6dYPAZIBpH tEEqSX0D8AypYamTkNbxUSMdpyWVHmqUn2xt186AUVimKNulWia0JtW3neRy4DXEm4fMo2 g54WLR1lJGdTjqASeXJ7PshV7HVnrJvILsy1i6+zocCNp/rI3gksyxJYXfqkLWRxEmtcLB T4nxvZo61pxPxyEYn23aOvFEq3hNImhPut4P8NXC0c+5eaZYqBVOFKPXsYuX0bKGbnCDqo Hb6qcWCkG06drca4EL35xM8z78r7lJjGUmQza625+nBGlGi7lKF7AzSdQHIWeA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4hgD2165hJz1CkT for ; Wed, 09 Sep 2026 21:08:57 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 689L8vAk075718 for ; Wed, 9 Sep 2026 21:08:57 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 689L8v7n075717 for python@FreeBSD.org; Wed, 9 Sep 2026 21:08:57 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" From: bugzilla-noreply@freebsd.org To: python@FreeBSD.org Subject: maintainer-feedback requested: [Bug 298351] devel/py-setuptools: CVE-2025-47273 remains flagged in 63.1.0_3; request update or security backport Port: devel/py-setuptools Installed package: py312-setuptools-63.1.0_3 System: FreeBSD 15, amd64 Ports branch: main `pkg audit` reports that py Date: Wed, 09 Sep 2026 21:08:57 +0000 X-Bugzilla-Type: request X-Bugzilla-Product: Ports & Packages X-Bugzilla-Component: Individual Port(s) X-Bugzilla-Version: Latest X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: python@FreeBSD.org X-Bugzilla-Flags: maintainer-feedback? Message-ID: In-Reply-To: References: X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: FreeBSD-specific Python issues List-Archive: https://lists.freebsd.org/archives/freebsd-python List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-python@freebsd.org Sender: owner-freebsd-python@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Bugzilla Automation has asked freebsd-python (Nobody) for maintainer-feedback: Bug 298351: devel/py-setuptools: CVE-2025-47273 remains flagged in 63.1.0_3; request update or security backport Port: devel/py-setuptools Installed package: py312-setuptools-63.1.0_3 System: FreeBSD 15, amd64 Ports branch: = main `pkg audit` reports that py https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D298351 --- Description --- Port: devel/py-setuptools Installed package: py312-setuptools-63.1.0_3 System: FreeBSD 15, amd64 Ports branch: main pkg audit reports that py312-setuptools-63.1.0_3 is affected by CVE-2025-47= 273, a path traversal vulnerability in setuptools PackageIndex. FreeBSD advisory: https://vuxml.freebsd.org/freebsd/690144e9-4f88-11f1-982e-00a098b42aeb.html The advisory lists setuptools versions before 78.1.1 as affected. My local ports tree is at commit d41a573a92e8. After fetching origin/main through commit 5e3a051d03e4, this command produced no output: git -C /usr/ports diff HEAD..origin/main -- devel/py-setuptools The port remains at: PORTVERSION=3D 63.1.0 PORTREVISION=3D 3 The Makefile applies upstream patch 6653e747c3815b140156249205397ef3719581e= e, which addresses deprecated pkgutil API usage in pkg_resources. There are no local files/patch-* files in this port. I did not find a backport of the CVE-2025-47273 fix in the inspected port configuration. On this system, py312-certbot-apache-4.2.0 depends on py312-setuptools, so removing the affected package would leave an installed dependency unsatisfi= ed. I have not established whether normal Certbot operation exposes the vulnera= ble code path. Could the port be updated to a fixed version, or could the security fix be backported if a major setuptools update requires broader ports compatibility testing? If the issue is already mitigated in this package, please clarify the mitigation and whether the VuXML affected-version range needs adjustment. Thank you.