/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-h22x-vf2g-j99v

Published

Last updated

https://images.chainguard.dev/security/CGA-h22x-vf2g-j99v
Package

pypy-3.10

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2022-37454
  • GHSA-6w4m-2xhg-2658

Severity

9.8

Critical

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-37454

Updates

Status

Not affected

Justification

Inline mitigations already exist

Impact

Upstream patched _sha3 module with the XKCP fix for CVE-2022-37454, reference:- https://github.com/python/cpython/pull/98519. Additionally, if linking Python 3.10 against OpenSSL 1.1.1 or later, the OpenSSL provided sha3 implementation will be used instead of the vulnerable bundled _sha3 XKCP module code. Reference:- https://github.com/python/cpython/issues/98517#issuecomment-1287317496

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing