Skip to content

python 3.12.15 and hwdata 0.412 - #173

Merged
DevomB merged 2 commits into
mainfrom
python-3.12.15
Oct 5, 2026
Merged

DevomB merged 2 commits into
mainfrom
python-3.12.15

Conversation

@DevomB

@DevomB DevomB commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Two upstreams released after main's last CI run, and both leave the pin gate red on the next push: NOT REVIEWED: python 3.12.14 -> 3.12.15 and NOT REVIEWED: hwdata 0.411 -> 0.412.

python 3.12.15 (2026-09-30) is a security release of the 3.12 series. Its changelog lists: the tarfile data and tar extraction filters letting a hard link to a symbolic link reach a file outside the destination (CVE-2026-82049), creating directories outside it for a name that leaves and returns, and ignoring a filter's refusal when a link falls back to a member; zipfile decompressing without a bound per read (CVE-2026-15310); a crash in ssl when an SNI callback switches contexts (CVE-2026-19445); wrap_bio() and asyncio's start_tls() not noticing a missing server_hostname; HTTPPasswordMgr offering an HTTPS URL's credentials to the same HTTP URL (CVE-2026-15806); stringprep and the idna codec reading code point attributes beyond RFC 3454; and a float formatting crash near INT_MAX. The bundled expat does not matter here: the final python links the system's 2.8.5. The net zone's fetcher and anything a user runs in a zone use this interpreter, so the pin moves instead of taking a review row. The lock records the tarball's hash, which python.org's release page also gives, and the signature verifies against the pinned 3.12 release key (7169605F…E5FA6305), so the gate pins nothing new.

hwdata 0.412 (2026-10-02) differs from 0.411 in pci.ids alone (the 2026-10-01 list) and its spec file's version. It has no signature upstream, so the lock's hash is what holds it, as before.

With both, check-source-currency.sh and check-pin-reviews.sh --no-held pass. A new source version starts stage 04 again from the stage 02 tree, so the Distro run on this branch is a full rebuild.

DevomB added 2 commits October 2, 2026 01:00
…tarfile's extraction filters inside the destination (CVE-2026-82049 and two more), bounds what zipfile decompresses per read (CVE-2026-15310), fixes the ssl crash in an SNI callback (CVE-2026-19445) and holds HTTPPasswordMgr's credentials to their scheme (CVE-2026-15806), signed by the pinned 3.12 release key
@DevomB
DevomB merged commit a1909f7 into main Oct 5, 2026
19 of 21 checks passed
@DevomB
DevomB deleted the python-3.12.15 branch October 5, 2026 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant