CVE-2025-13837

Updated: 2026-02-04 05:06:57.501916

Description:

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Alpine Linux 3.22 python 3.9 5.5 MEDIUM Released CLSA-2026:1771344045 2026-02-17 18:17:49
Alpine Linux 3.22 python 3.7 5.5 MEDIUM Released CLSA-2026:1771329661 2026-02-17 15:44:43
Alpine Linux 3.22 python 3.8 5.5 MEDIUM Released CLSA-2026:1771328976 2026-02-17 15:48:17
Alpine Linux 3.22 python 3.6 5.5 MEDIUM Released CLSA-2026:1771328044 2026-02-17 15:48:52
Debian 10 python 3.6 5.5 MEDIUM Released CLSA-2026:1771342739 2026-02-17 15:48:58
Debian 10 python 2.7 5.5 MEDIUM Needs Triage 2026-02-04 09:00:19
Debian 11 python 2.7 5.5 MEDIUM Needs Triage 2026-02-04 09:00:21
Debian 11 python 3.6 5.5 MEDIUM Released CLSA-2026:1771342958 2026-02-17 15:48:56
Debian 12 python 3.9 5.5 MEDIUM Released CLSA-2026:1771343618 2026-02-17 18:17:55
Debian 12 python 3.7 5.5 MEDIUM Released CLSA-2026:1771329439 2026-02-17 15:48:31
Total: 36