All errata/sisyphus_riscv64/ALT-PU-2026-7905-1
ALT-PU-2026-7905-1

Package update pspp in branch sisyphus_riscv64

Version2.1.1-alt1
Task#0
Published2026-05-15
Max severityCRITICAL
Severity:

Closed issues (5)

CVE-2025-47229
MEDIUM5.5

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a call from src/data/dictionary.c code into src/data/variable.c code.

Published: 2025-05-03Modified: 2026-06-17
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2025-48188
MEDIUM5.5

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.

Published: 2025-05-16Modified: 2026-06-17
CVSS 3.xMEDIUM 5.5
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N