--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9860efdad7
2026-01-25 01:15:35.207007+00:00
--------------------------------------------------------------------------------

Name        : python3.11
Product     : Fedora 42
Version     : 3.11.14
Release     : 4.fc42
URL         : https://www.python.org/
Summary     : Version 3.11 of the Python interpreter
Description :
Python 3.11 is an accessible, high-level, dynamically typed, interpreted
programming language, designed with an emphasis on code readability.
It includes an extensive standard library, and has a vast ecosystem of
third-party libraries.

The python3.11 package provides the "python3.11" executable: the reference
interpreter for the Python language, version 3.
The majority of its standard library is provided in the python3.11-libs package,
which should be installed automatically along with python3.11.
The remaining parts of the Python standard library are broken out into the
python3.11-tkinter and python3.11-test packages, which may need to be installed
separately.

Documentation for Python is provided in the python3.11-docs package.

Packages containing additional libraries for Python are generally named with
the "python3.11-" prefix.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2025-13836
Security fix for CVE-2025-12084
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan 16 2026 Lumír Balhar <[email protected]> - 3.11.14-4
- Security fix for CVE-2025-13836
* Thu Jan  8 2026 Lumír Balhar <[email protected]> - 3.11.14-3
- Security fix for CVE-2025-12084
* Tue Jan  6 2026 Karolina Surma <[email protected]> - 3.11.14-2
- Require at least the same expat version as used during the build time
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2421625 - CVE-2025-12084 python3.11: cpython: Quadratic algorithm 
in xml.dom.minidom leads to denial of service [fedora-42]
        https://bugzilla.redhat.com/show_bug.cgi?id=2421625
  [ 2 ] Bug #2428932 - CVE-2025-13836 python3.11: Excessive read buffering DoS 
in http.client [fedora-42]
        https://bugzilla.redhat.com/show_bug.cgi?id=2428932
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9860efdad7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to