Opened 6 weeks ago

Closed 6 days ago

#6007 closed enhancement (fixed)

Python-3.14.8 with several security fixes.

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: highest Milestone: 13.2
Component: Book Version: git
Severity: critical Keywords:
Cc:

Description

Recent security updates:

Subject: 	[Security-announce][CVE-2026-17084] StringPrep algorithm considered 
Unicode codepoint attributes outside Unicode 3.2.0
Date: 	Tue, 18 Aug 2026 13:55:39 +0000
From: 	Seth Larson <seth@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org

There is a MEDIUM severity vulnerability affecting CPython.

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or 
B.3 correctly: the latest Unicode codepoint attributes were used instead of the 
specified Unicode 3.2.0. This behavior would cause mismatches when processing 
domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function 
of the "stringprep" module. This only affects domain names containing characters 
that were not previously registered or had their Unicode attributes such as 
case-folding behavior updated since Unicode 3.2.0.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-17084
* https://github.com/python/cpython/pull/155293

Backport for the 3.14 branch: ​https://github.com/python/cpython/pull/156020

This is still open.

Subject: 	[Security-announce][CVE-2026-15806] urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme
Date: 	Tue, 18 Aug 2026 15:38:30 +0000
From: 	Kirill Podoprigora via Security-announce <security-announce@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org
CC: 	Kirill Podoprigora <kirill.bast@...il.com>


There is a MEDIUM severity vulnerability affecting CPython.

   The HTTPPasswordMgr class in the urllib.request module, along with its
subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth,
did not take the URL scheme into account when matching stored credentials
against a requested URL. Credentials added for an https:// URL were also used
for requests to the same host over http://, so an attacker able to redirect or
downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect
or an on-path position) could capture credentials in cleartext. Credentials
added for http:// URLs could likewise be sent over https://.

   Credential matching is now scoped by URL scheme. Credentials registered with
a URL that includes a scheme are only used for requests with the same scheme.
Credentials registered with a bare authority (such as example.com or
example.com:8080) continue to match any scheme, preserving compatibility with
existing code, including proxy authentication.

   Users who cannot upgrade immediately can mitigate by ensuring that
applications never make plain http:// requests to hosts for which credentials
are registered, for example by not following redirects to http:// URLs.

Please see the linked CVE ID for the latest information on affected versions:
- https://www.cve.org/CVERecord?id=CVE-2026-15806
- https://github.com/python/cpython/pull/155696

Backport for the 3.14 branch: ​https://github.com/python/cpython/pull/155969

Merged.

Subject: 	[Security-announce][CVE-2026-19672] tarfile extraction filter bypass allows creation of directories outside the destination
Date: 	Wed, 19 Aug 2026 14:56:06 +0100
From: 	Stan Ulbrych via Security-announce <security-announce@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org
CC: 	Stan Ulbrych <stanulbrych@...il.com>

There is a MEDIUM severity vulnerability affecting CPython.

The tarfile module's tar and data extraction filters created directories outside
the destination for members whose name leaves the destination and returns to it,
such as ../evil/../dest/sub/file. The containment check used the resolved path,
but intermediate directories were created from the name as given.

Only empty directories are created outside the destination. Member contents are
still extracted inside it. To return to the destination the member's name must
contain the destination directory's own final component, so extraction into a
secure randomised directory is not affected.

This affects POSIX platforms only. On Windows, .. components are collapsed
before the path reaches the filesystem, so the directories outside the
destination are never created.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-19672
* https://github.com/python/cpython/pull/156000

Backport for the 3.14 branch: ​https://github.com/python/cpython/pull/156041

Merged.

Change History (10)

comment:1 by Joe Locash, 8 days ago

Priority: normal → highest
Severity: normal → critical
Summary: Python security fixes: CVE-2026-17084,15806,19672 → Python security fixes: CVE-2026-17084,15806,19672,15310,87910,12345,19553,19445

Two more vulnerabilites were announced today, one is high and the other is critical. Also included are the minor ones previously announced.

Subject:	[Security-announce][CVE-2026-15310] Memory exhaustion in zipfile in
 bzip2/LZMA/Zstandard decompression
Date:	Tue, 25 Aug 2026 16:51:43 +0200
From:	Petr Viktorin via Security-announce <security-announce@...hon.org>
Reply-To:	security-sig@...hon.org
To: 	security-announce@...hon.org
Cc:	Petr Viktorin <encukou@..il.com>

There is a LOW severity vulnerability affecting CPython.

When decompressing crafted zip files using the bzip/LZMA/Zstandard
compressions, Python could use an attacker-controlled size to
pre-allocate memory, possibly resulting in memory exhaustion.

Please see the linked CVE ID for the latest information on affected
versions:

* https://www.cve.org/CVERecord?id=CVE-2026-15310
* https://github.com/python/cpython/pull/156003

3.14 fix: ​https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89

Subject: 	[Security-announce][CVE-2026-87910] tarfile hardlink fallback ignores 
custom extraction filter rejection via None
Date: 	Fri, 11 Sep 2026 14:24:10 +0200
From: 	Petr Viktorin via Security-announce <security-announce@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org
CC: 	Petr Viktorin <encukou@...il.com>

There is a MEDIUM severity vulnerability affecting CPython.

When tarfile extracts a link on a system that doesn't support links, it
falls back to extracting a member from the archive. In this case, the
filter function is run twice: once for the extracted member, and once
with name set to the location of the link.
For one of the calls, the return value was ignored. Instead, the member
should be skipped if either call returns None.

Please see the linked CVE ID for the latest information on affected
versions:

* https://www.cve.org/CVERecord?id=CVE-2026-87910
* https://github.com/python/cpython/pull/157266

3.14 backport: ​https://github.com/python/cpython/pull/157307

Subject: 	[Security-announce][CVE-2026-12345] Race condition in 
tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary 
directory
Date: 	Tue, 29 Sep 2026 18:28:51 +0100
From: 	Stan Ulbrych via Security-announce <security-announce@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org
CC: 	Stan Ulbrych <stanulbrych@...il.com>

There is a MEDIUM severity vulnerability affecting CPython.

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An 
attacker who can modify the tree during cleanup can replace a directory with a 
symbolic link, causing files outside of the temporary directory to be deleted or 
have their permissions and file flags reset, with the privileges of the process 
performing the cleanup.

Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain 
affected, and file flags may still be reset outside of the tree on all platforms.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-12345
* https://github.com/python/cpython/pull/157580

3.14 backport: ​https://github.com/python/cpython/pull/158430 (open)

Subject: 	[Security-announce][CVE-2026-19553] SSLContext.wrap_bio() missing 
validation of server_hostname parameter
Date: 	Wed, 30 Sep 2026 16:08:09 +0000
From: 	Seth Larson <seth@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org

There is a HIGH severity vulnerability affecting CPython.

`ssl.SSLContext.wrap_bio()` didn't require the `server_hostname` argument to not 
be `None` if `ssl.SSLContext.check_hostname` was set. Due to a missing parameter 
check in `SSLObject`, if the `server_hostname` argument isn't supplied then 
hostname verification would be silently skipped.

This defect could lead to programs where certificate hostname verification 
*appeared* to be succeeding with `SSLContext.check_hostname = True` and no 
`ValueError` being raised due to misconfiguration.

If the program passes a `server_hostname` value that isn't an empty string or 
`None` to any of these APIs then certificate hostname verification proceeds as 
expected and the program is not affected by this vulnerability.

Mitigating this vulnerability doesn't require updating Python or applying the 
patch. To mitigate, pass a valid non-`None` and non-empty `server_hostname` 
value to `SSLContext.wrap_bio()`, `asyncio.create_connection()`, or 
`asyncio.loop.start_tls()` and certificate hostname verification will proceed as 
expected. Upgrading to the latest version of Python or applying the patch only 
changes the behavior from silently skipping hostname verification to raising a 
`ValueError`, similar to `SSLContext.wrap_socket()`, when `server_hostname` 
isn't supplied.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-19553
* https://github.com/python/cpython/pull/158503

3.14 backport: ​https://github.com/python/cpython/pull/158509

Subject: 	[Security-announce][CVE-2026-19445] Use-after-free of a server-side 
SSLContext when sni_callback switches contexts
Date: 	Wed, 30 Sep 2026 16:10:08 +0000
From: 	Seth Larson <seth@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org

There is a CRITICAL severity vulnerability affecting CPython.

A remote, unauthenticated TLS client can make a server crash or call through a 
freed pointer if its sni_callback assigns a different context to 
SSLSocket.context (the documented way to select a certificate per server name) 
and nothing else keeps the original ssl.SSLContext alive. Typical cases are 
servers that create an SSLContext per connection or replace it while connections 
are open; servers that wrap their listening socket with it are not affected.

Mitigation: keep a reference to every SSLContext that sets sni_callback for the 
lifetime of the server. TLS clients are not affected.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-19445
* https://github.com/python/cpython/pull/158504

3.14 backport: ​https://github.com/python/cpython/pull/158515

comment:2 by Bruce Dubbs, 8 days ago

Summary: Python security fixes: CVE-2026-17084,15806,19672,15310,87910,12345,19553,19445 → Python security fixes. Waiting for next version of Python due October 1st.

The next version will be 3.15.

comment:3 by Bruce Dubbs, 7 days ago

Summary: Python security fixes. Waiting for next version of Python due October 1st. → Python-3.14.8 with several security fixes.

comment:4 by Bruce Dubbs, 7 days ago

I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.

in reply to:  4 ; comment:5 by Joe Locash, 7 days ago

Replying to Bruce Dubbs:

I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.

When I build this after a full LFS build it doesn't bomb for me?

in reply to:  5 ; comment:6 by Bruce Dubbs, 7 days ago

Replying to Joe Locash:

Replying to Bruce Dubbs:

I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.

When I build this after a full LFS build it doesn't bomb for me?

You built it without the patch?

in reply to:  6 comment:7 by Joe Locash, 7 days ago

Replying to Bruce Dubbs:

Replying to Joe Locash:

Replying to Bruce Dubbs:

I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.

When I build this after a full LFS build it doesn't bomb for me?

You built it without the patch?

Yes

comment:8 by Bruce Dubbs, 7 days ago

I tried building Python-3.14.8 in a full system, but ran into a couple of problems. I tried without the patch. This is from my log:

checking for stdlib extension module _ssl... yes
...
[ERROR] _ssl failed to import: /build/python/Python-3.14.8/build/lib.linux-x86_64-3.14/_ssl.cpython-314-x86_64-linux-gnu.so: undefined symbol: TLSv1_method
Following modules built successfully but were removed because they could not be imported:
_ssl                                                           

Could not build the ssl module!
Python requires a OpenSSL 1.1.1 or newer

I got that twice.

In the tests:

0:00:08 load avg: 4.31 [256/492/1] test_ssl skipped
test_ssl skipped -- No module named '_ssl'
...
1 test failed:
    test_importlib

Then during the install:

/usr/bin/install -c -m 755 Modules/_ssl.cpython-314-x86_64-linux-gnu.so /usr/lib/python3.14/lib-dynload/_ssl.cpython-314-x86_64-linux-gnu.so
install: cannot stat 'Modules/_ssl.cpython-314-x86_64-linux-gnu.so': No such file or directory
make: *** [Makefile:2569: sharedinstall] Error 1

The base executable, python3, was installed, but the process stopped at that point.

comment:9 by Bruce Dubbs, 6 days ago

Owner: changed from lfs-book to SecurityAdvisory

Updated at commit e640dd0f6. Leaving open for security advisory.

comment:10 by Bruce Dubbs, 6 days ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.1-044 has been issued.

Note: See TracTickets for help on using tickets.