#1148561 python-anyio: CVE-2026-64847 CVE-2026-63349 CVE-2026-63374

Package:
src:python-anyio
Source:
src:python-anyio
Submitter:
Moritz Mühlenhoff
Date:
2026-09-23 10:35:02 UTC
Severity:
normal
Tags:
#1148561#5
Date:
2026-09-20 18:42:00 UTC
From:
To:
Hi,

The following vulnerabilities were published for python-anyio.

CVE-2026-64847[0]:
| AnyIO is a high level asynchronous concurrency and networking
| framework that works on top of either Trio or asyncio. Prior to
| 4.14.2, AnyIO starts process-pool workers with standard error
| connected to a pipe that the parent never drains, even though the
| documented behavior redirects all three standard streams. Worker
| code that writes enough attacker-influenced data to sys.stderr can
| fill the pipe and block before returning the standard-output
| protocol response, causing the awaiting process-pool call to remain
| blocked indefinitely. Applications that run untrusted or faulty
| worker code capable of producing substantial standard-error output
| are affected. This issue is fixed in version 4.14.2.

https://github.com/agronholm/anyio/security/advisories/GHSA-5p39-cfhj-2xmp
https://github.com/agronholm/anyio/pull/1207
https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040 (4.14.2)


CVE-2026-63349[1]:
| AnyIO is a high level asynchronous concurrency and networking
| framework that works on top of either Trio or asyncio. In 4.14.0,
| AnyIO accepts the POSIX extra_groups argument in anyio.run_process()
| and anyio.open_process(), but open_process() forwards the group
| argument to the backend instead of extra_groups. A caller that
| supplies extra_groups=[] to clear inherited supplementary groups can
| therefore launch a child that retains the parent process groups,
| undermining a privilege-dropping boundary. If group is also
| supplied, the integer group value is passed where an iterable of
| supplementary groups is expected and the launch can fail with
| TypeError. This issue affects POSIX applications that rely on AnyIO
| subprocess helpers to launch less-privileged child processes. This
| issue is fixed in version 4.14.2.

https://github.com/agronholm/anyio/security/advisories/GHSA-3w57-8xmc-8v26
https://github.com/agronholm/anyio/pull/1209
https://github.com/agronholm/anyio/commit/eb562e6462ee46b1904e50b02ce00a858cdeb200 (4.14.2)



CVE-2026-63374[2]:
https://github.com/agronholm/anyio/security/advisories/GHSA-82r6-8w77-94w6



If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-64847
https://www.cve.org/CVERecord?id=CVE-2026-64847
[1] https://security-tracker.debian.org/tracker/CVE-2026-63349
https://www.cve.org/CVERecord?id=CVE-2026-63349
[2] https://security-tracker.debian.org/tracker/CVE-2026-63374
https://www.cve.org/CVERecord?id=CVE-2026-63374

Please adjust the affected versions in the BTS as needed.

#1148561#12
Date:
2026-09-23 10:33:51 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-anyio, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148561@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Colin Watson <cjwatson@debian.org> (supplier of updated python-anyio package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 23 Sep 2026 11:10:33 +0100
Source: python-anyio
Architecture: source
Version: 4.15.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Closes: 1145839 1148561
Changes:
 python-anyio (4.15.1-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release (closes: #1148561):
     - CVE-2026-63349: Fixed extra_groups not being passed to backend
       open_process().
     - CVE-2026-63374: Fixed TLSStream.wrap() using IDNA 2003 to encode host
       names.
     - CVE-2026-64847: Fixed stderr writes in a worker subprocess causing a
       deadlock.
     - Added support for Python 3.15 (closes: #1145839).
Checksums-Sha1:
 2110db19ce119aa862f132b3f3bd503f3e07b747 2853 python-anyio_4.15.1-1.dsc
 9b346640fcf19a0a153dec02352a4c73138684c6 270969 python-anyio_4.15.1.orig.tar.gz
 2bd6af374c03e8c985bf46c841c4b1385900ca8e 4728 python-anyio_4.15.1-1.debian.tar.xz
 ae8a56dea84dbe4b1f76aef2cb8a2eb2152f1dbb 621552 python-anyio_4.15.1-1.git.tar.xz
 741f19399e0ff1e23519b0877b295ed3350da323 17746 python-anyio_4.15.1-1_source.buildinfo
Checksums-Sha256:
 79bdc88eb8715aaf7f6710f492cb7e69f1fc101b423f026e7e7cb1d320b94f99 2853 python-anyio_4.15.1-1.dsc
 aa3b2dcf1e0dcdef16b9995a17afd4f8594d2b0c8e58721d7ab8a5b5fdb70ebf 270969 python-anyio_4.15.1.orig.tar.gz
 c240ccd9212ca9164775549bc58b85f045770350c506908290ccc2f4ec896f8d 4728 python-anyio_4.15.1-1.debian.tar.xz
 7a3046853a14e0e8b7f1cb4be62274b99f339c10a4eae99d84b5d2f760b6f23a 621552 python-anyio_4.15.1-1.git.tar.xz
 6a94c3e64a74273e26b0a622deddeb751d607422b6d4c42b29fae0f3ed958397 17746 python-anyio_4.15.1-1_source.buildinfo
Files:
 ef211b6fa90e525c97ecf38c06580ab6 2853 python optional python-anyio_4.15.1-1.dsc
 d514ae047d6d6f465114a3f9b79164fc 270969 python optional python-anyio_4.15.1.orig.tar.gz
 51dd83b3e2c0699398bac5d12e800583 4728 python optional python-anyio_4.15.1-1.debian.tar.xz
 bfb23d351c4ab8848242689c0c12b023 621552 python None python-anyio_4.15.1-1.git.tar.xz
 269d4b970684bb12b6fb4f0db47814bf 17746 python optional python-anyio_4.15.1-1_source.buildinfo
Git-Tag-Info: tag=cba1c76a791307793446ac9650759024f7d61b83 fp=ac0a4ff12611b6fccf01c111393587d97d86500b
Git-Tag-Tagger: Colin Watson <cjwatson@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqzpfoACgkQYG0ITkaD
wHn/ABAA4lCe0ani8zNzcGdufz0eLtSiiKLk0ObrCASWOjt3hQV/qZF517Mz/tkE
axfYD3nB1fzDhyMgzDFi+4Rd1nlLDbha1qRqNHyWOID2qLn0rR32VZK4wFA2AD42
Cf/BScuDLXNHnLr4nf2GyVPLQeLxFiMIT2jBstfV+Ls/IcrLs+LnNyL69VekTBoC
frparQHyMmRUBae5pMXG1I0Asav7IKN5HJ4OW14hFVkehBN+B0G/oxBBuDMhCR5u
SPYHl0sqNrXIOG2LbouuuyaE8FKcwSiLJsh5jTBHP5Rl7cfMniYvf6eLmEdO976s
VmqhXkyfAXWbWplwaB0re3lJY/zInu9myBO4nWrAsbPul3Z50Rr8e7ZZImsaI9xh
aBRYDOYUvJV3+jwqp8am1f7h7F9l/VDFprsXo3pZddZ7JtsKdwGh2owTh645eiKv
3/FtQr9yKT4ThBuKB64AHZNxOHTK5a9/e31943iB4qwo4LpnHBhjahWgvIkohfqH
Z97ETqlbdd9we5xuH9BR126/M1YgocoqZwBIPkezXUdAPRFmXmOZV89tsXmwlYuS
ebNF50aECfpXqEKacnRZw618cSGJXl0pYyBDDiTlk7F5QQtANHzFBNPsPMWL5Raj
6g458GRVkUvTqkKs7cOn3hkqnT9Z8iCEzuh7bLZBeepkd5ple4w=
=ZtgT
-----END PGP SIGNATURE-----