public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/python3.12] f44: Update to Python 3.12.14
@ 2026-08-17  9:34 Karolina Surma
  0 siblings, 0 replies; only message in thread
From: Karolina Surma @ 2026-08-17  9:34 UTC (permalink / raw)
  To: git-commits

A new commit has been pushed.

Repo   : rpms/python3.12
Branch : f44
Commit : 5590da14924ea625a8d1a40684162b9482b5578a
Author : Karolina Surma <ksurma@redhat.com>
Date   : 2026-08-14T11:29:07+02:00
Stats  : +34/-970 in 13 file(s)
URL    : https://src.fedoraproject.org/rpms/python3.12/c/5590da14924ea625a8d1a40684162b9482b5578a?branch=f44

Log:
Update to Python 3.12.14

---
diff --git a/00464-enable-pac-and-bti-protections-for-aarch64.patch b/00464-enable-pac-and-bti-protections-for-aarch64.patch
deleted file mode 100644
index 81729d2..0000000
--- a/00464-enable-pac-and-bti-protections-for-aarch64.patch
+++ /dev/null
@@ -1,102 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Charalampos Stratakis <cstratak@redhat.com>
-Date: Tue, 3 Jun 2025 03:02:15 +0200
-Subject: 00464: Enable PAC and BTI protections for aarch64
-
-Apply protection against ROP/JOP attacks for aarch64 on asm_trampoline.S
-
-The BTI flag must be applied in the assembler sources for this class
-of attacks to be mitigated on newer aarch64 processors.
-
-Upstream PR: https://github.com/python/cpython/pull/130864/files
-
-The upstream patch is incomplete but only for the case where
-frame pointers are not used on 3.13+.
-
-Since on Fedora we always compile with frame pointers the BTI/PAC
-hardware protections can be enabled without losing Perf unwinding.
----
- Python/asm_trampoline.S         |  4 +++
- Python/asm_trampoline_aarch64.h | 50 +++++++++++++++++++++++++++++++++
- 2 files changed, 54 insertions(+)
- create mode 100644 Python/asm_trampoline_aarch64.h
-
-diff --git a/Python/asm_trampoline.S b/Python/asm_trampoline.S
-index 341d0bbe51..ae882660b5 100644
---- a/Python/asm_trampoline.S
-+++ b/Python/asm_trampoline.S
-@@ -1,3 +1,5 @@
-+#include "asm_trampoline_aarch64.h"
-+
-     .text
-     .globl	_Py_trampoline_func_start
- # The following assembly is equivalent to:
-@@ -20,10 +22,12 @@ _Py_trampoline_func_start:
- #if defined(__aarch64__) && defined(__AARCH64EL__) && !defined(__ILP32__)
-     // ARM64 little endian, 64bit ABI
-     // generate with aarch64-linux-gnu-gcc 12.1
-+    SIGN_LR
-     stp     x29, x30, [sp, -16]!
-     mov     x29, sp
-     blr     x3
-     ldp     x29, x30, [sp], 16
-+    VERIFY_LR
-     ret
- #endif
-     .globl	_Py_trampoline_func_end
-diff --git a/Python/asm_trampoline_aarch64.h b/Python/asm_trampoline_aarch64.h
-new file mode 100644
-index 0000000000..4b0ec4a7dc
---- /dev/null
-+++ b/Python/asm_trampoline_aarch64.h
-@@ -0,0 +1,50 @@
-+#ifndef ASM_TRAMPOLINE_AARCH_64_H_
-+#define ASM_TRAMPOLINE_AARCH_64_H_
-+
-+/*
-+ * References:
-+ *  - https://developer.arm.com/documentation/101028/0012/5--Feature-test-macros
-+ *  - https://github.com/ARM-software/abi-aa/blob/main/aaelf64/aaelf64.rst
-+ */
-+
-+#if defined(__ARM_FEATURE_BTI_DEFAULT) && __ARM_FEATURE_BTI_DEFAULT == 1
-+  #define BTI_J hint 36 /* bti j: for jumps, IE br instructions */
-+  #define BTI_C hint 34  /* bti c: for calls, IE bl instructions */
-+  #define GNU_PROPERTY_AARCH64_BTI 1 /* bit 0 GNU Notes is for BTI support */
-+#else
-+  #define BTI_J
-+  #define BTI_C
-+  #define GNU_PROPERTY_AARCH64_BTI 0
-+#endif
-+
-+#if defined(__ARM_FEATURE_PAC_DEFAULT)
-+  #if __ARM_FEATURE_PAC_DEFAULT & 1
-+    #define SIGN_LR hint 25 /* paciasp: sign with the A key */
-+    #define VERIFY_LR hint 29 /* autiasp: verify with the A key */
-+  #elif __ARM_FEATURE_PAC_DEFAULT & 2
-+    #define SIGN_LR hint 27 /* pacibsp: sign with the b key */
-+    #define VERIFY_LR hint 31 /* autibsp: verify with the b key */
-+  #endif
-+  #define GNU_PROPERTY_AARCH64_POINTER_AUTH 2 /* bit 1 GNU Notes is for PAC support */
-+#else
-+  #define SIGN_LR BTI_C
-+  #define VERIFY_LR
-+  #define GNU_PROPERTY_AARCH64_POINTER_AUTH 0
-+#endif
-+
-+/* Add the BTI and PAC support to GNU Notes section */
-+#if GNU_PROPERTY_AARCH64_BTI != 0 || GNU_PROPERTY_AARCH64_POINTER_AUTH != 0
-+    .pushsection .note.gnu.property, "a"; /* Start a new allocatable section */
-+    .balign 8; /* align it on a byte boundry */
-+    .long 4; /* size of "GNU\0" */
-+    .long 0x10; /* size of descriptor */
-+    .long 0x5; /* NT_GNU_PROPERTY_TYPE_0 */
-+    .asciz "GNU";
-+    .long 0xc0000000; /* GNU_PROPERTY_AARCH64_FEATURE_1_AND */
-+    .long 4; /* Four bytes of data */
-+    .long (GNU_PROPERTY_AARCH64_BTI|GNU_PROPERTY_AARCH64_POINTER_AUTH); /* BTI or PAC is enabled */
-+    .long 0; /* padding for 8 byte alignment */
-+    .popsection; /* end the section */
-+#endif
-+
-+#endif

diff --git a/00478-cve-2026-4519.patch b/00478-cve-2026-4519.patch
deleted file mode 100644
index 8598b76..0000000
--- a/00478-cve-2026-4519.patch
+++ /dev/null
@@ -1,105 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Pinky <pinky00ch@gmail.com>
-Date: Wed, 25 Mar 2026 01:02:37 +0530
-Subject: 00478: CVE-2026-4519
-
-Reject leading dashes in webbrowser URLs (GH-146360)
-
-(cherry picked from commit 82a24a4442312bdcfc4c799885e8b3e00990f02b)
-
-Co-authored-by: Seth Michael Larson <seth@python.org>
----
- Lib/test/test_webbrowser.py                          |  5 +++++
- Lib/webbrowser.py                                    | 12 ++++++++++++
- .../2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst   |  1 +
- 3 files changed, 18 insertions(+)
- create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst
-
-diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py
-index 2d695bc883..60f094fd6a 100644
---- a/Lib/test/test_webbrowser.py
-+++ b/Lib/test/test_webbrowser.py
-@@ -59,6 +59,11 @@ def test_open(self):
-                    options=[],
-                    arguments=[URL])
- 
-+    def test_reject_dash_prefixes(self):
-+        browser = self.browser_class(name=CMD_NAME)
-+        with self.assertRaises(ValueError):
-+            browser.open(f"--key=val {URL}")
-+
- 
- class BackgroundBrowserCommandTest(CommandTestMixin, unittest.TestCase):
- 
-diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py
-index 13b9e85f9e..0bdb644d7d 100755
---- a/Lib/webbrowser.py
-+++ b/Lib/webbrowser.py
-@@ -158,6 +158,12 @@ def open_new(self, url):
-     def open_new_tab(self, url):
-         return self.open(url, 2)
- 
-+    @staticmethod
-+    def _check_url(url):
-+        """Ensures that the URL is safe to pass to subprocesses as a parameter"""
-+        if url and url.lstrip().startswith("-"):
-+            raise ValueError(f"Invalid URL: {url}")
-+
- 
- class GenericBrowser(BaseBrowser):
-     """Class for all browsers started with a command
-@@ -175,6 +181,7 @@ def __init__(self, name):
- 
-     def open(self, url, new=0, autoraise=True):
-         sys.audit("webbrowser.open", url)
-+        self._check_url(url)
-         cmdline = [self.name] + [arg.replace("%s", url)
-                                  for arg in self.args]
-         try:
-@@ -195,6 +202,7 @@ def open(self, url, new=0, autoraise=True):
-         cmdline = [self.name] + [arg.replace("%s", url)
-                                  for arg in self.args]
-         sys.audit("webbrowser.open", url)
-+        self._check_url(url)
-         try:
-             if sys.platform[:3] == 'win':
-                 p = subprocess.Popen(cmdline)
-@@ -260,6 +268,7 @@ def _invoke(self, args, remote, autoraise, url=None):
- 
-     def open(self, url, new=0, autoraise=True):
-         sys.audit("webbrowser.open", url)
-+        self._check_url(url)
-         if new == 0:
-             action = self.remote_action
-         elif new == 1:
-@@ -350,6 +359,7 @@ class Konqueror(BaseBrowser):
- 
-     def open(self, url, new=0, autoraise=True):
-         sys.audit("webbrowser.open", url)
-+        self._check_url(url)
-         # XXX Currently I know no way to prevent KFM from opening a new win.
-         if new == 2:
-             action = "newTab"
-@@ -554,6 +564,7 @@ def register_standard_browsers():
-     class WindowsDefault(BaseBrowser):
-         def open(self, url, new=0, autoraise=True):
-             sys.audit("webbrowser.open", url)
-+            self._check_url(url)
-             try:
-                 os.startfile(url)
-             except OSError:
-@@ -638,6 +649,7 @@ def _name(self, val):
- 
-         def open(self, url, new=0, autoraise=True):
-             sys.audit("webbrowser.open", url)
-+            self._check_url(url)
-             if self.name == 'default':
-                 script = 'open location "%s"' % url.replace('"', '%22') # opens in default browser
-             else:
-diff --git a/Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst b/Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst
-new file mode 100644
-index 0000000000..0f27eae99a
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst
-@@ -0,0 +1 @@
-+Reject leading dashes in URLs passed to :func:`webbrowser.open`

diff --git a/00479-cve-2026-1502.patch b/00479-cve-2026-1502.patch
deleted file mode 100644
index 16dc99b..0000000
--- a/00479-cve-2026-1502.patch
+++ /dev/null
@@ -1,107 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Seth Larson <seth@python.org>
-Date: Fri, 10 Apr 2026 10:21:42 -0500
-Subject: 00479: CVE-2026-1502
-
-Reject CR/LF in HTTP tunnel request headers
-
-Co-authored-by: Illia Volochii <illia.volochii@gmail.com>
----
- Lib/http/client.py                            | 11 ++++-
- Lib/test/test_httplib.py                      | 45 +++++++++++++++++++
- ...-03-20-09-29-42.gh-issue-146211.PQVbs7.rst |  2 +
- 3 files changed, 57 insertions(+), 1 deletion(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst
-
-diff --git a/Lib/http/client.py b/Lib/http/client.py
-index 70451d67d4..7db4807b30 100644
---- a/Lib/http/client.py
-+++ b/Lib/http/client.py
-@@ -972,13 +972,22 @@ def _wrap_ipv6(self, ip):
-         return ip
- 
-     def _tunnel(self):
-+        if _contains_disallowed_url_pchar_re.search(self._tunnel_host):
-+            raise ValueError('Tunnel host can\'t contain control characters %r'
-+                             % (self._tunnel_host,))
-         connect = b"CONNECT %s:%d %s\r\n" % (
-             self._wrap_ipv6(self._tunnel_host.encode("idna")),
-             self._tunnel_port,
-             self._http_vsn_str.encode("ascii"))
-         headers = [connect]
-         for header, value in self._tunnel_headers.items():
--            headers.append(f"{header}: {value}\r\n".encode("latin-1"))
-+            header_bytes = header.encode("latin-1")
-+            value_bytes = value.encode("latin-1")
-+            if not _is_legal_header_name(header_bytes):
-+                raise ValueError('Invalid header name %r' % (header_bytes,))
-+            if _is_illegal_header_value(value_bytes):
-+                raise ValueError('Invalid header value %r' % (value_bytes,))
-+            headers.append(b"%s: %s\r\n" % (header_bytes, value_bytes))
-         headers.append(b"\r\n")
-         # Making a single send() call instead of one per line encourages
-         # the host OS to use a more optimal packet size instead of
-diff --git a/Lib/test/test_httplib.py b/Lib/test/test_httplib.py
-index e46dac0077..e027d930d9 100644
---- a/Lib/test/test_httplib.py
-+++ b/Lib/test/test_httplib.py
-@@ -369,6 +369,51 @@ def test_invalid_headers(self):
-                 with self.assertRaisesRegex(ValueError, 'Invalid header'):
-                     conn.putheader(name, value)
- 
-+    def test_invalid_tunnel_headers(self):
-+        cases = (
-+            ('Invalid\r\nName', 'ValidValue'),
-+            ('Invalid\rName', 'ValidValue'),
-+            ('Invalid\nName', 'ValidValue'),
-+            ('\r\nInvalidName', 'ValidValue'),
-+            ('\rInvalidName', 'ValidValue'),
-+            ('\nInvalidName', 'ValidValue'),
-+            (' InvalidName', 'ValidValue'),
-+            ('\tInvalidName', 'ValidValue'),
-+            ('Invalid:Name', 'ValidValue'),
-+            (':InvalidName', 'ValidValue'),
-+            ('ValidName', 'Invalid\r\nValue'),
-+            ('ValidName', 'Invalid\rValue'),
-+            ('ValidName', 'Invalid\nValue'),
-+            ('ValidName', 'InvalidValue\r\n'),
-+            ('ValidName', 'InvalidValue\r'),
-+            ('ValidName', 'InvalidValue\n'),
-+        )
-+        for name, value in cases:
-+            with self.subTest((name, value)):
-+                conn = client.HTTPConnection('example.com')
-+                conn.set_tunnel('tunnel', headers={
-+                    name: value
-+                })
-+                conn.sock = FakeSocket('')
-+                with self.assertRaisesRegex(ValueError, 'Invalid header'):
-+                    conn._tunnel()  # Called in .connect()
-+
-+    def test_invalid_tunnel_host(self):
-+        cases = (
-+            'invalid\r.host',
-+            '\ninvalid.host',
-+            'invalid.host\r\n',
-+            'invalid.host\x00',
-+            'invalid host',
-+        )
-+        for tunnel_host in cases:
-+            with self.subTest(tunnel_host):
-+                conn = client.HTTPConnection('example.com')
-+                conn.set_tunnel(tunnel_host)
-+                conn.sock = FakeSocket('')
-+                with self.assertRaisesRegex(ValueError, 'Tunnel host can\'t contain control characters'):
-+                    conn._tunnel()  # Called in .connect()
-+
-     def test_headers_debuglevel(self):
-         body = (
-             b'HTTP/1.1 200 OK\r\n'
-diff --git a/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst b/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst
-new file mode 100644
-index 0000000000..4993633b8e
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-03-20-09-29-42.gh-issue-146211.PQVbs7.rst
-@@ -0,0 +1,2 @@
-+Reject CR/LF characters in tunnel request headers for the
-+HTTPConnection.set_tunnel() method.

diff --git a/00480-cve-2026-4786.patch b/00480-cve-2026-4786.patch
deleted file mode 100644
index 73e4e13..0000000
--- a/00480-cve-2026-4786.patch
+++ /dev/null
@@ -1,64 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <stan@python.org>
-Date: Mon, 13 Apr 2026 20:02:52 +0100
-Subject: 00480: CVE-2026-4786
-
-Fix webbrowser `%action` substitution bypass of dash-prefix check
----
- Lib/test/test_webbrowser.py                              | 9 +++++++++
- Lib/webbrowser.py                                        | 5 +++--
- .../2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst       | 2 ++
- 3 files changed, 14 insertions(+), 2 deletions(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst
-
-diff --git a/Lib/test/test_webbrowser.py b/Lib/test/test_webbrowser.py
-index 60f094fd6a..e900c0212b 100644
---- a/Lib/test/test_webbrowser.py
-+++ b/Lib/test/test_webbrowser.py
-@@ -99,6 +99,15 @@ def test_open_new_tab(self):
-                    options=[],
-                    arguments=[URL])
- 
-+    def test_reject_action_dash_prefixes(self):
-+        browser = self.browser_class(name=CMD_NAME)
-+        with self.assertRaises(ValueError):
-+            browser.open('%action--incognito')
-+        # new=1: action is "--new-window", so "%action" itself expands to
-+        # a dash-prefixed flag even with no dash in the original URL.
-+        with self.assertRaises(ValueError):
-+            browser.open('%action', new=1)
-+
- 
- class EdgeCommandTest(CommandTestMixin, unittest.TestCase):
- 
-diff --git a/Lib/webbrowser.py b/Lib/webbrowser.py
-index 0bdb644d7d..79d410bcae 100755
---- a/Lib/webbrowser.py
-+++ b/Lib/webbrowser.py
-@@ -268,7 +268,6 @@ def _invoke(self, args, remote, autoraise, url=None):
- 
-     def open(self, url, new=0, autoraise=True):
-         sys.audit("webbrowser.open", url)
--        self._check_url(url)
-         if new == 0:
-             action = self.remote_action
-         elif new == 1:
-@@ -282,7 +281,9 @@ def open(self, url, new=0, autoraise=True):
-             raise Error("Bad 'new' parameter to open(); " +
-                         "expected 0, 1, or 2, got %s" % new)
- 
--        args = [arg.replace("%s", url).replace("%action", action)
-+        self._check_url(url.replace("%action", action))
-+
-+        args = [arg.replace("%action", action).replace("%s", url)
-                 for arg in self.remote_args]
-         args = [arg for arg in args if arg]
-         success = self._invoke(args, True, autoraise, url)
-diff --git a/Misc/NEWS.d/next/Security/2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst b/Misc/NEWS.d/next/Security/2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst
-new file mode 100644
-index 0000000000..45cdeebe1b
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst
-@@ -0,0 +1,2 @@
-+A bypass in :mod:`webbrowser` allowed URLs prefixed with ``%action`` to pass
-+the dash-prefix safety check.

diff --git a/00482-cve-2026-6100.patch b/00482-cve-2026-6100.patch
deleted file mode 100644
index 5656e3d..0000000
--- a/00482-cve-2026-6100.patch
+++ /dev/null
@@ -1,61 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <stan@python.org>
-Date: Mon, 13 Apr 2026 02:14:54 +0100
-Subject: 00482: CVE-2026-6100
-
-Fix a possible UAF in {LZMA,BZ2,_Zlib}Decompressor
----
- .../Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst  | 5 +++++
- Modules/_bz2module.c                                         | 1 +
- Modules/_lzmamodule.c                                        | 1 +
- Modules/zlibmodule.c                                         | 1 +
- 4 files changed, 8 insertions(+)
- create mode 100644 Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst
-
-diff --git a/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst b/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst
-new file mode 100644
-index 0000000000..9502189ab1
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-04-10-16-28-21.gh-issue-148395.kfzm0G.rst
-@@ -0,0 +1,5 @@
-+Fix a dangling input pointer in :class:`lzma.LZMADecompressor`,
-+:class:`bz2.BZ2Decompressor`, and internal :class:`!zlib._ZlibDecompressor`
-+when memory allocation fails with :exc:`MemoryError`, which could let a
-+subsequent :meth:`!decompress` call read or write through a stale pointer to
-+the already-released caller buffer.
-diff --git a/Modules/_bz2module.c b/Modules/_bz2module.c
-index 97bd44b4ac..a732e89d55 100644
---- a/Modules/_bz2module.c
-+++ b/Modules/_bz2module.c
-@@ -587,6 +587,7 @@ decompress(BZ2Decompressor *d, char *data, size_t len, Py_ssize_t max_length)
-     return result;
- 
- error:
-+    bzs->next_in = NULL;
-     Py_XDECREF(result);
-     return NULL;
- }
-diff --git a/Modules/_lzmamodule.c b/Modules/_lzmamodule.c
-index 7bbd6569aa..103a6ef86c 100644
---- a/Modules/_lzmamodule.c
-+++ b/Modules/_lzmamodule.c
-@@ -1114,6 +1114,7 @@ decompress(Decompressor *d, uint8_t *data, size_t len, Py_ssize_t max_length)
-     return result;
- 
- error:
-+    lzs->next_in = NULL;
-     Py_XDECREF(result);
-     return NULL;
- }
-diff --git a/Modules/zlibmodule.c b/Modules/zlibmodule.c
-index f94c57e4c8..9759593b6a 100644
---- a/Modules/zlibmodule.c
-+++ b/Modules/zlibmodule.c
-@@ -1645,6 +1645,7 @@ decompress(ZlibDecompressor *self, uint8_t *data,
-     return result;
- 
- error:
-+    self->zst.next_in = NULL;
-     Py_XDECREF(result);
-     return NULL;
- }

diff --git a/00483-cve-2026-2297.patch b/00483-cve-2026-2297.patch
deleted file mode 100644
index 8b504c9..0000000
--- a/00483-cve-2026-2297.patch
+++ /dev/null
@@ -1,33 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Steve Dower <steve.dower@python.org>
-Date: Wed, 4 Mar 2026 19:55:52 +0000
-Subject: 00483: CVE-2026-2297
-
-Logging Bypass in Legacy .pyc File Handling
----
- Lib/importlib/_bootstrap_external.py                            | 2 +-
- .../Security/2026-03-04-18-59-17.gh-issue-145506.6hwvEh.rst     | 2 ++
- 2 files changed, 3 insertions(+), 1 deletion(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-03-04-18-59-17.gh-issue-145506.6hwvEh.rst
-
-diff --git a/Lib/importlib/_bootstrap_external.py b/Lib/importlib/_bootstrap_external.py
-index 9b8a8dfc5a..6e4a087a10 100644
---- a/Lib/importlib/_bootstrap_external.py
-+++ b/Lib/importlib/_bootstrap_external.py
-@@ -1186,7 +1186,7 @@ def get_filename(self, fullname):
- 
-     def get_data(self, path):
-         """Return the data from path as raw bytes."""
--        if isinstance(self, (SourceLoader, ExtensionFileLoader)):
-+        if isinstance(self, (SourceLoader, SourcelessFileLoader, ExtensionFileLoader)):
-             with _io.open_code(str(path)) as file:
-                 return file.read()
-         else:
-diff --git a/Misc/NEWS.d/next/Security/2026-03-04-18-59-17.gh-issue-145506.6hwvEh.rst b/Misc/NEWS.d/next/Security/2026-03-04-18-59-17.gh-issue-145506.6hwvEh.rst
-new file mode 100644
-index 0000000000..dcdb44d4fa
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-03-04-18-59-17.gh-issue-145506.6hwvEh.rst
-@@ -0,0 +1,2 @@
-+Fixes :cve:`2026-2297` by ensuring that ``SourcelessFileLoader`` uses
-+:func:`io.open_code` when opening ``.pyc`` files.

diff --git a/00484-cve-2026-3644.patch b/00484-cve-2026-3644.patch
deleted file mode 100644
index a1c12bd..0000000
--- a/00484-cve-2026-3644.patch
+++ /dev/null
@@ -1,146 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <89152624+StanFromIreland@users.noreply.github.com>
-Date: Mon, 16 Mar 2026 13:43:43 +0000
-Subject: 00484: CVE-2026-3644
-
-Incomplete control character validation in http.cookies
-
-Co-authored-by: Victor Stinner <victor.stinner@gmail.com>
----
- Lib/http/cookies.py                           | 24 ++++++++++--
- Lib/test/test_http_cookies.py                 | 38 +++++++++++++++++++
- ...-03-06-17-03-38.gh-issue-145599.kchwZV.rst |  4 ++
- 3 files changed, 62 insertions(+), 4 deletions(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-03-06-17-03-38.gh-issue-145599.kchwZV.rst
-
-diff --git a/Lib/http/cookies.py b/Lib/http/cookies.py
-index d0a69cbe19..63d119ad46 100644
---- a/Lib/http/cookies.py
-+++ b/Lib/http/cookies.py
-@@ -335,9 +335,16 @@ def update(self, values):
-             key = key.lower()
-             if key not in self._reserved:
-                 raise CookieError("Invalid attribute %r" % (key,))
-+            if _has_control_character(key, val):
-+                raise CookieError("Control characters are not allowed in "
-+                                  f"cookies {key!r} {val!r}")
-             data[key] = val
-         dict.update(self, data)
- 
-+    def __ior__(self, values):
-+        self.update(values)
-+        return self
-+
-     def isReservedKey(self, K):
-         return K.lower() in self._reserved
- 
-@@ -363,9 +370,15 @@ def __getstate__(self):
-         }
- 
-     def __setstate__(self, state):
--        self._key = state['key']
--        self._value = state['value']
--        self._coded_value = state['coded_value']
-+        key = state['key']
-+        value = state['value']
-+        coded_value = state['coded_value']
-+        if _has_control_character(key, value, coded_value):
-+            raise CookieError("Control characters are not allowed in cookies "
-+                              f"{key!r} {value!r} {coded_value!r}")
-+        self._key = key
-+        self._value = value
-+        self._coded_value = coded_value
- 
-     def output(self, attrs=None, header="Set-Cookie:"):
-         return "%s %s" % (header, self.OutputString(attrs))
-@@ -377,13 +390,16 @@ def __repr__(self):
- 
-     def js_output(self, attrs=None):
-         # Print javascript
-+        output_string = self.OutputString(attrs)
-+        if _has_control_character(output_string):
-+            raise CookieError("Control characters are not allowed in cookies")
-         return """
-         <script type="text/javascript">
-         <!-- begin hiding
-         document.cookie = \"%s\";
-         // end hiding -->
-         </script>
--        """ % (self.OutputString(attrs).replace('"', r'\"'))
-+        """ % (output_string.replace('"', r'\"'))
- 
-     def OutputString(self, attrs=None):
-         # Build up our result
-diff --git a/Lib/test/test_http_cookies.py b/Lib/test/test_http_cookies.py
-index f196bcc48e..2478a6c630 100644
---- a/Lib/test/test_http_cookies.py
-+++ b/Lib/test/test_http_cookies.py
-@@ -573,6 +573,14 @@ def test_control_characters(self):
-             with self.assertRaises(cookies.CookieError):
-                 morsel["path"] = c0
- 
-+            # .__setstate__()
-+            with self.assertRaises(cookies.CookieError):
-+                morsel.__setstate__({'key': c0, 'value': 'val', 'coded_value': 'coded'})
-+            with self.assertRaises(cookies.CookieError):
-+                morsel.__setstate__({'key': 'key', 'value': c0, 'coded_value': 'coded'})
-+            with self.assertRaises(cookies.CookieError):
-+                morsel.__setstate__({'key': 'key', 'value': 'val', 'coded_value': c0})
-+
-             # .setdefault()
-             with self.assertRaises(cookies.CookieError):
-                 morsel.setdefault("path", c0)
-@@ -587,6 +595,18 @@ def test_control_characters(self):
-             with self.assertRaises(cookies.CookieError):
-                 morsel.set("path", "val", c0)
- 
-+            # .update()
-+            with self.assertRaises(cookies.CookieError):
-+                morsel.update({"path": c0})
-+            with self.assertRaises(cookies.CookieError):
-+                morsel.update({c0: "val"})
-+
-+            # .__ior__()
-+            with self.assertRaises(cookies.CookieError):
-+                morsel |= {"path": c0}
-+            with self.assertRaises(cookies.CookieError):
-+                morsel |= {c0: "val"}
-+
-     def test_control_characters_output(self):
-         # Tests that even if the internals of Morsel are modified
-         # that a call to .output() has control character safeguards.
-@@ -607,6 +627,24 @@ def test_control_characters_output(self):
-             with self.assertRaises(cookies.CookieError):
-                 cookie.output()
- 
-+        # Tests that .js_output() also has control character safeguards.
-+        for c0 in support.control_characters_c0():
-+            morsel = cookies.Morsel()
-+            morsel.set("key", "value", "coded-value")
-+            morsel._key = c0  # Override private variable.
-+            cookie = cookies.SimpleCookie()
-+            cookie["cookie"] = morsel
-+            with self.assertRaises(cookies.CookieError):
-+                cookie.js_output()
-+
-+            morsel = cookies.Morsel()
-+            morsel.set("key", "value", "coded-value")
-+            morsel._coded_value = c0  # Override private variable.
-+            cookie = cookies.SimpleCookie()
-+            cookie["cookie"] = morsel
-+            with self.assertRaises(cookies.CookieError):
-+                cookie.js_output()
-+
- 
- def load_tests(loader, tests, pattern):
-     tests.addTest(doctest.DocTestSuite(cookies))
-diff --git a/Misc/NEWS.d/next/Security/2026-03-06-17-03-38.gh-issue-145599.kchwZV.rst b/Misc/NEWS.d/next/Security/2026-03-06-17-03-38.gh-issue-145599.kchwZV.rst
-new file mode 100644
-index 0000000000..e53a932d12
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-03-06-17-03-38.gh-issue-145599.kchwZV.rst
-@@ -0,0 +1,4 @@
-+Reject control characters in :class:`http.cookies.Morsel`
-+:meth:`~http.cookies.Morsel.update` and
-+:meth:`~http.cookies.BaseCookie.js_output`.
-+This addresses :cve:`2026-3644`.

diff --git a/00485-cve-2026-4224.patch b/00485-cve-2026-4224.patch
deleted file mode 100644
index 14f8734..0000000
--- a/00485-cve-2026-4224.patch
+++ /dev/null
@@ -1,98 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Stan Ulbrych <89152624+StanFromIreland@users.noreply.github.com>
-Date: Sun, 15 Mar 2026 21:46:06 +0000
-Subject: 00485: CVE-2026-4224
-MIME-Version: 1.0
-Content-Type: text/plain; charset=UTF-8
-Content-Transfer-Encoding: 8bit
-
-Stack overflow parsing XML with deeply nested DTD content models
-
-Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>
----
- Lib/test/test_pyexpat.py                       | 18 ++++++++++++++++++
- ...6-03-14-17-31-39.gh-issue-145986.ifSSr8.rst |  4 ++++
- Modules/pyexpat.c                              |  9 ++++++++-
- 3 files changed, 30 insertions(+), 1 deletion(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst
-
-diff --git a/Lib/test/test_pyexpat.py b/Lib/test/test_pyexpat.py
-index 38f951573f..37d9086f40 100644
---- a/Lib/test/test_pyexpat.py
-+++ b/Lib/test/test_pyexpat.py
-@@ -675,6 +675,24 @@ def test_change_size_2(self):
-         parser.Parse(xml2, True)
-         self.assertEqual(self.n, 4)
- 
-+class ElementDeclHandlerTest(unittest.TestCase):
-+    def test_deeply_nested_content_model(self):
-+        # This should raise a RecursionError and not crash.
-+        # See https://github.com/python/cpython/issues/145986.
-+        N = 500_000
-+        data = (
-+            b'<!DOCTYPE root [\n<!ELEMENT root '
-+            + b'(a, ' * N + b'a' + b')' * N
-+            + b'>\n]>\n<root/>\n'
-+        )
-+
-+        parser = expat.ParserCreate()
-+        parser.ElementDeclHandler = lambda _1, _2: None
-+        with support.infinite_recursion():
-+            with self.assertRaises(RecursionError):
-+                parser.Parse(data)
-+
-+
- class MalformedInputTest(unittest.TestCase):
-     def test1(self):
-         xml = b"\0\r\n"
-diff --git a/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst b/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst
-new file mode 100644
-index 0000000000..79536d1fef
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst
-@@ -0,0 +1,4 @@
-+:mod:`xml.parsers.expat`: Fixed a crash caused by unbounded C recursion when
-+converting deeply nested XML content models with
-+:meth:`~xml.parsers.expat.xmlparser.ElementDeclHandler`.
-+This addresses :cve:`2026-4224`.
-diff --git a/Modules/pyexpat.c b/Modules/pyexpat.c
-index 79492ca5c4..8673540f35 100644
---- a/Modules/pyexpat.c
-+++ b/Modules/pyexpat.c
-@@ -3,6 +3,7 @@
- #endif
- 
- #include "Python.h"
-+#include "pycore_ceval.h"           // _Py_EnterRecursiveCall()
- #include "pycore_runtime.h"         // _Py_ID()
- #include <ctype.h>
- 
-@@ -578,6 +579,10 @@ static PyObject *
- conv_content_model(XML_Content * const model,
-                    PyObject *(*conv_string)(const XML_Char *))
- {
-+    if (_Py_EnterRecursiveCall(" in conv_content_model")) {
-+        return NULL;
-+    }
-+
-     PyObject *result = NULL;
-     PyObject *children = PyTuple_New(model->numchildren);
-     int i;
-@@ -589,7 +594,7 @@ conv_content_model(XML_Content * const model,
-                                                  conv_string);
-             if (child == NULL) {
-                 Py_XDECREF(children);
--                return NULL;
-+                goto done;
-             }
-             PyTuple_SET_ITEM(children, i, child);
-         }
-@@ -597,6 +602,8 @@ conv_content_model(XML_Content * const model,
-                                model->type, model->quant,
-                                conv_string,model->name, children);
-     }
-+done:
-+    _Py_LeaveRecursiveCall();
-     return result;
- }
- 

diff --git a/00490-cve-2026-15308.patch b/00490-cve-2026-15308.patch
deleted file mode 100644
index 942b18b..0000000
--- a/00490-cve-2026-15308.patch
+++ /dev/null
@@ -1,114 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Serhiy Storchaka <storchaka@gmail.com>
-Date: Sat, 4 Jul 2026 20:40:22 +0300
-Subject: 00490: gh-153030: Fix quadratic complexity in incremental parsing in
- HTMLParser
-
-When an unterminated construct (e.g. a tag or comment) spanned many
-feed() calls, rescanning the growing buffer and concatenating new data
-onto it were both quadratic.  New data is now accumulated in a list and
-only joined and parsed once enough has piled up.
-(cherry picked from commit bcf98ddbc40ec9b3ee87da0124a5660b19b7e606)
-
-Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
-Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
----
- Lib/html/parser.py                            | 32 +++++++++++++++++--
- Lib/test/test_htmlparser.py                   | 20 ++++++++++++
- ...-07-04-17-00-00.gh-issue-153030.RovkP6.rst |  3 ++
- 3 files changed, 53 insertions(+), 2 deletions(-)
- create mode 100644 Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst
-
-diff --git a/Lib/html/parser.py b/Lib/html/parser.py
-index bfab3e64cd..c5d2340b71 100644
---- a/Lib/html/parser.py
-+++ b/Lib/html/parser.py
-@@ -138,6 +138,9 @@ def reset(self):
-         self.cdata_elem = None
-         self._support_cdata = True
-         self._escapable = True
-+        self._pending = []
-+        self._pending_len = 0
-+        self._parse_threshold = 1
-         super().reset()
- 
-     def feed(self, data):
-@@ -146,11 +149,36 @@ def feed(self, data):
-         Call this as often as you want, with as little or as much text
-         as you want (may include '\n').
-         """
--        self.rawdata = self.rawdata + data
--        self.goahead(0)
-+        # Accumulate new data in a list and only join and parse it once
-+        # enough has piled up.  Rescanning an unparsed buffer (e.g. an
-+        # unterminated tag) and concatenating onto it on every call would
-+        # both be quadratic in the input size.
-+        self._pending_len += len(data)
-+        if self._pending_len < self._parse_threshold:
-+            self._pending.append(data)
-+        else:
-+            if not self._pending:
-+                self.rawdata += data
-+            else:
-+                self._pending.append(data)
-+                self.rawdata += ''.join(self._pending)
-+                self._pending.clear()
-+            self._pending_len = 0
-+            n = len(self.rawdata)
-+            self.goahead(0)
-+            if len(self.rawdata) < n:
-+                # Some data was parsed; resume on the next call.
-+                self._parse_threshold = 1
-+            else:
-+                # Nothing was parsed; wait until the buffer doubles.
-+                self._parse_threshold = len(self.rawdata)
- 
-     def close(self):
-         """Handle any buffered data."""
-+        if self._pending:
-+            self.rawdata += ''.join(self._pending)
-+            self._pending.clear()
-+            self._pending_len = 0
-         self.goahead(1)
- 
-     __starttag_text = None
-diff --git a/Lib/test/test_htmlparser.py b/Lib/test/test_htmlparser.py
-index 303c0baa87..e6d92a7ec5 100644
---- a/Lib/test/test_htmlparser.py
-+++ b/Lib/test/test_htmlparser.py
-@@ -930,6 +930,26 @@ def check(source):
-         check("<![CDATA[" * 9 * n)
-         check("<!doctype" * 35 * n)
- 
-+    @support.requires_resource('cpu')
-+    def test_incremental_no_quadratic_complexity(self):
-+        # An unterminated construct fed in many small chunks used to take
-+        # quadratic time, both to rescan and to concatenate the buffer.
-+        # Now it takes a fraction of a second.
-+        def check(prefix, chunk, suffix):
-+            parser = html.parser.HTMLParser()
-+            parser.feed(prefix)
-+            for _ in range(200_000):
-+                parser.feed(chunk)
-+            parser.feed(suffix)
-+            parser.close()
-+        chunk = "a" * 64
-+        check("<!--", chunk, "-->")       # comment
-+        check("<?", chunk, ">")           # processing instruction
-+        check("<!doctype ", chunk, ">")   # doctype
-+        check("<![CDATA[", chunk, "]]>")  # CDATA section
-+        check("<a href='", chunk, "'>")   # start tag
-+        check("<script>", chunk, "</script>")  # RAWTEXT element
-+
- 
- class AttributesTestCase(TestCaseBase):
- 
-diff --git a/Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst b/Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst
-new file mode 100644
-index 0000000000..d1d60593f4
---- /dev/null
-+++ b/Misc/NEWS.d/next/Security/2026-07-04-17-00-00.gh-issue-153030.RovkP6.rst
-@@ -0,0 +1,3 @@
-+Fixed quadratic complexity in incremental parsing of long unterminated
-+constructs (such as tags or comments) in :class:`html.parser.HTMLParser`,
-+which could be exploited for a denial of service.

diff --git a/00491-gh-149776-skip-udp-lite-tests-if-it-s-not-supported.patch b/00491-gh-149776-skip-udp-lite-tests-if-it-s-not-supported.patch
deleted file mode 100644
index 1419963..0000000
--- a/00491-gh-149776-skip-udp-lite-tests-if-it-s-not-supported.patch
+++ /dev/null
@@ -1,63 +0,0 @@
-From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
-From: Victor Stinner <vstinner@python.org>
-Date: Wed, 13 May 2026 17:27:56 +0200
-Subject: 00491: gh-149776: Skip UDP Lite tests if it's not supported
-
-Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if
-it's not supported.
-
-(cherry picked from commit 3cfc249e11a132dc69624150843779aa96c72b2b)
-(cherry picked from commit 49d08674d8dba50dc29539e3c7bce21d66066b06)
----
- Lib/test/test_socket.py                       | 21 ++++++++++++++++++-
- ...-05-13-14-53-23.gh-issue-149776.orqgsn.rst |  2 ++
- 2 files changed, 22 insertions(+), 1 deletion(-)
- create mode 100644 Misc/NEWS.d/next/Tests/2026-05-13-14-53-23.gh-issue-149776.orqgsn.rst
-
-diff --git a/Lib/test/test_socket.py b/Lib/test/test_socket.py
-index f200fc9792..9453a2c7e8 100644
---- a/Lib/test/test_socket.py
-+++ b/Lib/test/test_socket.py
-@@ -157,6 +157,25 @@ def _have_socket_hyperv():
-     return True
- 
- 
-+def _have_udp_lite():
-+    if not hasattr(socket, "IPPROTO_UDPLITE"):
-+        return False
-+    # Older Android versions block UDPLITE with SELinux.
-+    if support.is_android and platform.android_ver().api_level < 29:
-+        return False
-+
-+    try:
-+        sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDPLITE)
-+    except OSError as exc:
-+        # Linux 7.1 removed UDP Lite support
-+        if exc.errno == errno.EPROTONOSUPPORT:
-+            return False
-+        raise
-+    sock.close()
-+
-+    return True
-+
-+
- @contextlib.contextmanager
- def socket_setdefaulttimeout(timeout):
-     old_timeout = socket.getdefaulttimeout()
-@@ -181,7 +200,7 @@ def socket_setdefaulttimeout(timeout):
- 
- HAVE_SOCKET_VSOCK = _have_socket_vsock()
- 
--HAVE_SOCKET_UDPLITE = hasattr(socket, "IPPROTO_UDPLITE")
-+HAVE_SOCKET_UDPLITE = _have_udp_lite()
- 
- HAVE_SOCKET_BLUETOOTH = _have_socket_bluetooth()
- 
-diff --git a/Misc/NEWS.d/next/Tests/2026-05-13-14-53-23.gh-issue-149776.orqgsn.rst b/Misc/NEWS.d/next/Tests/2026-05-13-14-53-23.gh-issue-149776.orqgsn.rst
-new file mode 100644
-index 0000000000..e86a9130ff
---- /dev/null
-+++ b/Misc/NEWS.d/next/Tests/2026-05-13-14-53-23.gh-issue-149776.orqgsn.rst
-@@ -0,0 +1,2 @@
-+Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it's
-+not supported. Patch by Victor Stinner.

diff --git a/00494-increase-the-timeout-of-test_large_content_length_truncated.patch b/00494-increase-the-timeout-of-test_large_content_length_truncated.patch
new file mode 100644
index 0000000..9d0ef51
--- /dev/null
+++ b/00494-increase-the-timeout-of-test_large_content_length_truncated.patch
@@ -0,0 +1,23 @@
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: Karolina Surma <ksurma@redhat.com>
+Date: Fri, 14 Aug 2026 09:38:26 +0200
+Subject: 00494: Increase the timeout of test_large_content_length_truncated
+
+It has started to fail randomly when run on s390x architecture.
+---
+ Lib/test/test_httpservers.py | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/Lib/test/test_httpservers.py b/Lib/test/test_httpservers.py
+index 96fc9ca574..6a3f5731a4 100644
+--- a/Lib/test/test_httpservers.py
++++ b/Lib/test/test_httpservers.py
+@@ -907,7 +907,7 @@ def test_large_content_length(self):
+             self.assertEqual(res.read(), b'%d %d' % (size, size) + self.linesep)
+ 
+     def test_large_content_length_truncated(self):
+-        with support.swap_attr(self.request_handler, 'timeout', 0.001):
++        with support.swap_attr(self.request_handler, 'timeout', support.LOOPBACK_TIMEOUT):
+             for w in range(18, 65):
+                 size = 1 << w
+                 headers = {'Content-Length' : str(size)}

diff --git a/python3.12.spec b/python3.12.spec
index c3b0ce6..0c61ac1 100644
--- a/python3.12.spec
+++ b/python3.12.spec
@@ -13,11 +13,11 @@ URL: https://www.python.org/
 
 #  WARNING  When rebasing to a new Python version,
 #           remember to update the python3-docs package as well
-%global general_version %{pybasever}.13
+%global general_version %{pybasever}.14
 #global prerel ...
 %global upstream_version %{general_version}%{?prerel}
 Version: %{general_version}%{?prerel:~%{prerel}}
-Release: 6%{?dist}
+Release: 1%{?dist}
 License: Python-2.0.1
 
 
@@ -400,23 +400,6 @@ Patch461: 00461-downstream-only-install-wheel-in-test-venvs-when-setuptools-71.p
 # stressed on OpenSSL 3.5.
 Patch462: 00462-fix-pyssl_seterror-handling-ssl_error_syscall.patch
 
-# 00464 # 1c713e02a26bf8865bb6421749d19d0766cac178
-# Enable PAC and BTI protections for aarch64
-#
-# Apply protection against ROP/JOP attacks for aarch64 on asm_trampoline.S
-#
-# The BTI flag must be applied in the assembler sources for this class
-# of attacks to be mitigated on newer aarch64 processors.
-#
-# Upstream PR: https://github.com/python/cpython/pull/130864/files
-#
-# The upstream patch is incomplete but only for the case where
-# frame pointers are not used on 3.13+.
-#
-# Since on Fedora we always compile with frame pointers the BTI/PAC
-# hardware protections can be enabled without losing Perf unwinding.
-Patch464: 00464-enable-pac-and-bti-protections-for-aarch64.patch
-
 # 00474 # 837ddca0372fa87ff9cee47142200caa21e77def
 # CVE-2025-15366
 #
@@ -433,63 +416,11 @@ Patch474: 00474-cve-2025-15366.patch
 # (cherry-picked from commit b234a2b67539f787e191d2ef19a7cbdce32874e7)
 Patch475: 00475-cve-2025-15367.patch
 
-# 00478 # eb93352dc8e31f4d52546b84daad875e6ff7f29e
-# CVE-2026-4519
-#
-# Reject leading dashes in webbrowser URLs (GH-146360)
-Patch478: 00478-cve-2026-4519.patch
-
-# 00479 # 97404b2cf62e545c2d41be7ccfed4e74da9ee665
-# CVE-2026-1502
-#
-# Reject CR/LF in HTTP tunnel request headers
-Patch479: 00479-cve-2026-1502.patch
-
-# 00480 # 6f4eef3ba4d9818a53698e994550ee8db17a1e2e
-# CVE-2026-4786
-#
-# Fix webbrowser `%%action` substitution bypass of dash-prefix check
-Patch480: 00480-cve-2026-4786.patch
-
-# 00482 # 69f14bc306fc62400d45565faa980b77858b9151
-# CVE-2026-6100
-#
-# Fix a possible UAF in {LZMA,BZ2,_Zlib}Decompressor
-Patch482: 00482-cve-2026-6100.patch
-
-# 00483 # 577c595137ce6ff92158ddaf2d7b7ea86437825d
-# CVE-2026-2297
+# 00494 # 430aab133397ed44cc9ee621fd311e02fee317b5
+# Increase the timeout of test_large_content_length_truncated
 #
-# Logging Bypass in Legacy .pyc File Handling
-Patch483: 00483-cve-2026-2297.patch
-
-# 00484 # 8b5133c1ab17a060cd134bea2a4b6e1831c47fed
-# CVE-2026-3644
-#
-# Incomplete control character validation in http.cookies
-Patch484: 00484-cve-2026-3644.patch
-
-# 00485 # 12a5b206676927bcee131ab4f2bd6783d2f5914a
-# CVE-2026-4224
-#
-# Stack overflow parsing XML with deeply nested DTD content models
-Patch485: 00485-cve-2026-4224.patch
-
-# 00490 # 3e8c5ad70d6a515107352d8779269240a0553f54
-# gh-153030: Fix quadratic complexity in incremental parsing in HTMLParser
-#
-# When an unterminated construct (e.g. a tag or comment) spanned many
-# feed() calls, rescanning the growing buffer and concatenating new data
-# onto it were both quadratic.  New data is now accumulated in a list and
-# only joined and parsed once enough has piled up.
-Patch490: 00490-cve-2026-15308.patch
-
-# 00491 # 1ad95144c42a6933283352245c5df5a4c142e75f
-# gh-149776: Skip UDP Lite tests if it's not supported
-#
-# Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if
-# it's not supported.
-Patch491: 00491-gh-149776-skip-udp-lite-tests-if-it-s-not-supported.patch
+# It has started to fail randomly when run on s390x architecture.
+Patch494: 00494-increase-the-timeout-of-test_large_content_length_truncated.patch
 
 # (New patches go here ^^^)
 #
@@ -1827,6 +1758,9 @@ CheckPython optimized
 # ======================================================
 
 %changelog
+* Thu Aug 13 2026 Karolina Surma <ksurma@redhat.com> - 3.12.14-1
+- Update to Python 3.12.14
+
 * Tue Jul 28 2026 Lukáš Zachar <lzachar@redhat.com> - 3.12.13-6
 - Security fix for CVE-2026-15308
 Resolves: rhbz#2498688

diff --git a/sources b/sources
index 5b33098..f116187 100644
--- a/sources
+++ b/sources
@@ -1,2 +1,2 @@
-SHA512 (Python-3.12.13.tar.xz) = e1eb66f0b34581f0155e3ce25ba72cf0b4b1107672ed0ad3e86bcfe616945c9204c41ffc492f32b1066b9154913ff88343038967ad8711dd05e6f2332fdb735b
-SHA512 (Python-3.12.13.tar.xz.asc) = 903fd3baa7e29891bb00fb159ec9c43804a71002c4cd38902d25bf4e5167f856b37d211a5b1098ee60e1ea41f8a10a1596dd2382edc6d7367d55dd4154807fc7
+SHA512 (Python-3.12.14.tar.xz) = 9007399ffdd3a493c91a98cd7a6cb93acfb8de80f3be2f5480cda36f134d49b5043a60bc6b5c62ed18cc6a2e4e3c81cb7556ac5f337e2cd58ff3449a8099ed22
+SHA512 (Python-3.12.14.tar.xz.asc) = 69cc4757f5d79ea46f9b632d5b34f9f16855cb1f767f77c827ad65546ba8f77b68e75a661ebc4e4f453edd7a98a73d916491597f67d4fed9c891aa599a869324

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-17  9:34 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-17  9:34 [rpms/python3.12] f44: Update to Python 3.12.14 Karolina Surma

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox