Opened 8 months ago
Closed 8 months ago
#22754 closed enhancement (fixed)
python3-3.14.3 (Wait for LFS)
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (6)
comment:1 by , 8 months ago
comment:2 by , 8 months ago
I 100% agree with you there, not only for time consuming searches like this one, but also so that we know where to look in the event of a security issue that gets caused by the sed/patch/etc.
comment:3 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 8 months ago
| Priority: | normal → elevated |
|---|
Security changes for Python-3.14.3:
Security
gh-144125: BytesGenerator will now refuse to serialize (write) headers that are
unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas
Bloemsaat and Petr Viktorin in gh-121650).
gh-143935: Fixed a bug in the folding of comments when flattening an email message
using a modern email policy. Comments consisting of a very long sequence of non-foldable
characters could trigger a forced line wrap that omitted the required leading space on
the continuation line, causing the remainder of the comment to be interpreted as a new
header field. This enabled header injection with carefully crafted inputs.
gh-143925: Reject control characters in data: URL media types.
gh-143919: Reject control characters in http.cookies.Morsel fields and values.
gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields,
values, and parameters.
comment:5 by , 8 months ago
There are too many changes in this version to post here. See Python-3.14.3/Misc/NEWS in the tarball for the full list.
comment:6 by , 8 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at commits
fc6f531da1 Update to Python-3.14.3. 5671b237b7 Update to shadow-4.19.3.
Note:
See TracTickets
for help on using tickets.

The sed should be removed. Note that the upstream change added the inserted line into a different location so it may not seem obvious.
BTW I'd propose we must put a reference to the upstream ticket/change when adding a patch or sed (in the patch file, or XML comment, or the Git commit message). Otherwise it will be so time-wasting to investigate a case like this one.