Skip to content

Move gh-157190 to the 3.10-3.13 block, mention 3.14+ not vulnerable - #155

Merged
hugovk merged 1 commit into
mainfrom
gh-157190
Oct 7, 2026
Merged

hugovk merged 1 commit into
mainfrom
gh-157190

Conversation

@hugovk

@hugovk hugovk commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Re: https://discuss.python.org/t/python-3-10-22-3-11-17-3-12-15-3-13-16-and-3-14-8-are-now-available/109296/10

Another question is why these security issues are not mentioned in proper changelogs on https://docs.python.org/3.*/whatsnew/changelog.html (for example, except for 3.13.8, none of them mentions gh-157190).

Specifically about gh-157190, the issue says:

This was incidentally fixed by 5a57248 for 3.14+ which changed os.link to use AT_SYMLINK_FOLLOW.

And CVE-2026-82049 says 3.14.8 isn't affected:

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable...

affected

  • affected from 0 before 3.10.22
  • affected from 3.11.0 before 3.11.17
  • affected from 3.12.0 before 3.12.15
  • affected from 3.13.0 before 3.13.16
  • affected from 3.14.0a1 before 3.14.0b1

So let's move it out of the 3.10-3.14 block into the 3.10-3.13 block, and add that:

Python 3.14 and later were already protected because os.link() follows symbolic links since Python 3.14.0b1 (gh-81793).

I've updated https://www.python.org/downloads/release/python-3148/ in the same way.

@psf-cabotage-us-east-2
psf-cabotage-us-east-2 Bot temporarily deployed to python/python-insider/pr-155 October 7, 2026 12:16 Destroyed
@psf-cabotage-us-east-2

psf-cabotage-us-east-2 Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Branch Deploy for pr-155 in Python Insider

Environment has been destroyed.

@hugovk
hugovk merged commit 084af88 into main Oct 7, 2026
5 checks passed
@hugovk
hugovk deleted the gh-157190 branch October 7, 2026 19:17

This branch was successfully deployed

No deployments
python/python-insider/pr-155 — 270d0173 Deployed Oct 7, 2026 by psf-cabotage-us-east-2[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant