Repository navigation
python 3.12.15 and hwdata 0.412 - #173
Merged
Merged
Conversation
…tarfile's extraction filters inside the destination (CVE-2026-82049 and two more), bounds what zipfile decompresses per read (CVE-2026-15310), fixes the ssl crash in an SNI callback (CVE-2026-19445) and holds HTTPPasswordMgr's credentials to their scheme (CVE-2026-15806), signed by the pinned 3.12 release key
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two upstreams released after main's last CI run, and both leave the pin gate red on the next push:
NOT REVIEWED: python 3.12.14 -> 3.12.15andNOT REVIEWED: hwdata 0.411 -> 0.412.python 3.12.15 (2026-09-30) is a security release of the 3.12 series. Its changelog lists: the tarfile
dataandtarextraction filters letting a hard link to a symbolic link reach a file outside the destination (CVE-2026-82049), creating directories outside it for a name that leaves and returns, and ignoring a filter's refusal when a link falls back to a member; zipfile decompressing without a bound per read (CVE-2026-15310); a crash in ssl when an SNI callback switches contexts (CVE-2026-19445);wrap_bio()and asyncio'sstart_tls()not noticing a missingserver_hostname; HTTPPasswordMgr offering an HTTPS URL's credentials to the same HTTP URL (CVE-2026-15806); stringprep and the idna codec reading code point attributes beyond RFC 3454; and a float formatting crash nearINT_MAX. The bundled expat does not matter here: the final python links the system's 2.8.5. The net zone's fetcher and anything a user runs in a zone use this interpreter, so the pin moves instead of taking a review row. The lock records the tarball's hash, which python.org's release page also gives, and the signature verifies against the pinned 3.12 release key (7169605F…E5FA6305), so the gate pins nothing new.hwdata 0.412 (2026-10-02) differs from 0.411 in
pci.idsalone (the 2026-10-01 list) and its spec file's version. It has no signature upstream, so the lock's hash is what holds it, as before.With both,
check-source-currency.shandcheck-pin-reviews.sh --no-heldpass. A new source version starts stage 04 again from the stage 02 tree, so the Distro run on this branch is a full rebuild.