Re: [Buildroot] [PATCH 2025.02.x] package/python3: security bump to v3.12.14

Titouan Christophe via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
Hi Thomas,

On 13/08/26 16:52, Thomas Perale via buildroot wrote:
> See the release notes: https://www.python.org/downloads/release/python-31214/
>
> - CVE-2026-7210
>
> https://github.com/python/cpython/issues/149018
> https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b
>
> - CVE-2026-4519
>
> https://github.com/python/cpython/issues/143930
> https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48
>
> - CVE-2026-3644
>
> https://github.com/python/cpython/issues/145599
> https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330
>
> - CVE-2026-15308
>
>   https://github.com/python/cpython/issues/153030
> https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14
>
> - CVE-2025-13462
>
> https://github.com/python/cpython/issues/141707
> https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084
>
> - CVE-2026-2297
>
> https://github.com/python/cpython/issues/145506
> https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66
>
> - CVE-2026-4224
>
> https://github.com/python/cpython/issues/145986
> https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621
>
> - CVE‑2026‑4360
>
> https://github.com/python/cpython/issues/151987
> https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92
>
> - CVE‑2026‑0864
>
> https://github.com/python/cpython/issues/143927
> https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
>
> - CVE‑2026‑1502
>
> https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec
> https://github.com/python/cpython/issues/146211
>
> - CVE‑2026‑3087
>
> https://github.com/python/cpython/commit/a6650a2cdf0c49fb8ce0c982903aa2aa274beefe
> https://github.com/python/cpython/issues/146581
>
> - CVE‑2026‑4786
>
> https://github.com/python/cpython/issues/148169
> https://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744
>
> - CVE‑2026‑6100
>
> https://github.com/python/cpython/issues/148395
> https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3
>
> - CVE‑2026‑6879
>
> https://github.com/python/cpython/issues/152674
> https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02
>
> - CVE‑2026‑11972
>
> https://github.com/python/cpython/issues/151981
> https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438
>
> - CVE‑2026‑12003
>
> https://github.com/python/cpython/issues/151544
> https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06
>
> The CVE-2026-3276, CVE-2026-7774, CVE-2026-8328, CVE-2026-9669,
> CVE-2026-11940 were already fixed with a backport on 2025.02.x.
>
> Signed-off-by: Thomas Perale <[email protected]>
I already had a similar commit, but with a more concise message.
I updated my commit with your detailed CVE list, and added you as 
Co-authored-by.

With this,
Applied to 2025.02.x, thanks !
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.