-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 12 May 2026 12:17:27 +0700 Source: python3.11 Binary: idle-python3.11 libpython3.11-testsuite python3.11-doc python3.11-examples Architecture: all Version: 3.11.2-6+deb12u8 Distribution: bookworm Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Arnaud Rebillout Description: idle-python3.11 - IDE for Python (v3.11) using Tkinter libpython3.11-testsuite - Testsuite for the Python standard library (v3.11) python3.11-doc - Documentation for the high-level object-oriented language Python python3.11-examples - Examples for the Python language (v3.11) Changes: python3.11 (3.11.2-6+deb12u8) bookworm; urgency=medium . * Non-maintainer upload. * Apply upstream patches for the following CVEs: - CVE-2025-13462: Incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined - CVE-2026-2297: SourcelessFileLoader does not use io.open_code() - CVE-2026-3644: Reject control characters in more places in http.cookies.Morsel (follow-up of patch for CVE-2026-0672) - CVE-2026-4224: pyexpat.c: Unbounded C recursion in conv_content_model causes crash - CVE-2026-4519: Reject leading dashes in webbrowser.open() - CVE-2026-6100: Possible UAF in {LZMA,BZ2}Decompressor * Add patch to skip some failing XML tests. Failure is due to the fact that we build / tests against expat/2.5.0-1+deb12u2, which was patched for CVE-2023-52425, and that broke some tests. See the patch itself for more details. Checksums-Sha1: f9488f27ffa4716257b17a0c02a0c02209cc3220 358272 idle-python3.11_3.11.2-6+deb12u8_all.deb 5be1245b1b10a221c3735f2b5446a0837ecc97c0 3374468 libpython3.11-testsuite_3.11.2-6+deb12u8_all.deb d4a9ab01ca393dc30872e1ea65f14be24cfcfe73 12642400 python3.11-doc_3.11.2-6+deb12u8_all.deb ae13c977e990a6a08d3594bbf2269ee3ae30330b 798636 python3.11-examples_3.11.2-6+deb12u8_all.deb ace1edcb96b8dd71cc54b12088fc21be2ae09993 12589 python3.11_3.11.2-6+deb12u8_all-buildd.buildinfo Checksums-Sha256: dfec304fd2dfb8c5aeeb47c9d0fbc151e841d8c82eaf72a8028d85e17ac7e2da 358272 idle-python3.11_3.11.2-6+deb12u8_all.deb 718afaa9807bcc228d16f7e01436f7fdbfc1268f806091c0b83d57f564633fa3 3374468 libpython3.11-testsuite_3.11.2-6+deb12u8_all.deb 50eb63e7f636c4281e9ce1b8f10386f1def42159eddce34fc1f41c46261df71b 12642400 python3.11-doc_3.11.2-6+deb12u8_all.deb d88b7cea4c907b683f3a1b4b73a830827ddce1d30fbf032d765650f45ac7df2f 798636 python3.11-examples_3.11.2-6+deb12u8_all.deb 7f2127ae020544dff9f31c2299d9cc9aeb31fc2fc6575f3827f05fa534f8942b 12589 python3.11_3.11.2-6+deb12u8_all-buildd.buildinfo Files: 6f92caaa0f5df76ee30fe74de47d498e 358272 python optional idle-python3.11_3.11.2-6+deb12u8_all.deb 56cbbbd199576aeac7b8abe295f2e0cb 3374468 libdevel optional libpython3.11-testsuite_3.11.2-6+deb12u8_all.deb ca2ceb3e33e566091235180aa76ed692 12642400 doc optional python3.11-doc_3.11.2-6+deb12u8_all.deb 0fb71ab725df08dbb72516a354eb59c0 798636 python optional python3.11-examples_3.11.2-6+deb12u8_all.deb 067cbe75c9861e6394009e38cb5bf552 12589 python optional python3.11_3.11.2-6+deb12u8_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmoTUOwACgkQmgPNRvTf /zc2IQ/+MKQTJO2L02f578iYy5mlf8itoIrHICwOjj62BpYCNhfs7XhE2E42Nvfc jeYKP74YREQPY6kGjlD0cK9doHVR/WbmNY60XUdMTo1GmazIKyGcp2Zl8Tn4KakS hm+5hNdre8qq49J48Ix+WEDY7lHNzteWCigUOTgfn+CWY0KuVFJ+sTN0Uc0creNb 1Db+Ka0IcGwXuWYAdiIpMklXIaxF27tmQZONmmncUD8MilVP/u/EJfsSv2Ay8OF1 0kbfoXEbTtIc7V+yZ0EEHIFSYYvBJlBWmlFEHbmAKqwOUdA0WqNF7ipt5UEijZte gfegd0Tjny+Yb/LWEK73GLbrOFNZyzyY+VEAXYrK/yfiV7uTQzUO9mOB/PH+ILLV bOfcJEGom8zVL4cHkqa6tdFU5jTCeJ4aGyM7igdtGD21AczK6/xidMxxVLlOpTam +ljVpU02cDONQjx7t3TIzTBrZkActWoQ2tjCbHcWrQ6TtKbqsI/IdLSbx7+bcGw8 DJ86YmTQyJrGiqdSd+eRQt9Z5ZzAR6YQUPhmShorwSYb4vt31C5tJfl2dZKQtmuk RHXGuCv4gB+TQ6ot91yg5aVylX5UnxMTaAnDc3L+QhWFxaTxybIKvco2Ru4kRIiW 6BHwe2ZcCHeJePgBgQnV4reSgHluvVv8RQd6tIPW4MSxiXtuKpY= =tjZQ -----END PGP SIGNATURE-----