Package Release Info

python313-3.13.14-160000.1.1

Update Info: Base Release
Available in Package Hub : 16.0

platforms

AArch64
ppc64le
s390x
x86-64

subpackages

python313-32bit

Change Logs

* Wed Jun 17 2026 mcepl@cepl.eu
- Update to 3.13.14:
  - Security
  - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android.
  - gh-150599: Fix a possible stack buffer overflow in bz2 when
    a bz2.BZ2Decompressor is reused after a decompression
    error. The decompressor now becomes unusable after libbz2
    reports an error.
  - gh-149835: shutil.move() now resolves symlinks via
    os.path.realpath() when checking whether the destination is
    inside the source directory, preventing a symlink-based
    bypass of that guard.
  - gh-149698: Update bundled libexpat to version 2.8.1 for the
    fix for CVE 2026-45186.
  - gh-87451: The ftplib module’s undocumented ftpcp function
    no longer trusts the IPv4 address value returned from the
    source server in response to the PASV command by default,
    completing the fix for CVE-2021-4189. As with ftplib.FTP,
    the former behavior can be re-enabled by setting the
    trust_server_pasv_ipv4_address attribute on the source
    ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape
    AI for the report.
  - gh-149486: tarfile.data_filter() now validates link targets
    using the same normalised value that is written to disk,
    strips trailing separators from the member name when
    resolving a symlink’s directory, and rejects link members
    that would replace the destination directory itself. This
    closes several path-traversal bypasses of the data
    extraction filter.
  - gh-149079: Fix a potential denial of service in
    unicodedata.normalize(). The canonical ordering step of
    Unicode normalization used a quadratic-time insertion sort
    for reordering combining characters, which could be
    exploited with crafted input containing many combining
    characters in non-canonical order. Replaced with
    a linear-time counting sort for long runs.
  - gh-149018: Improved protection against XML hash-flooding
    attacks in xml.parsers.expat and xml.etree.ElementTree when
    Python is compiled with libExpat 2.8.0 or later.
  - gh-149017: Update bundled libexpat to version 2.8.0.
  - gh-90309: Base64-encode values when embedding cookies to
    JavaScript using the http.cookies.BaseCookie.js_output()
    method to avoid injection and escaping. (bsc#1262654,
    CVE-2026-6019)
  - gh-148808: Added buffer boundary check when using nbytes
    parameter with
    asyncio.AbstractEventLoop.sock_recvfrom_into(). Only
    relevant for Windows and the asyncio.ProactorEventLoop.
  - gh-148395: Fix a dangling input pointer in
    lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal
    zlib._ZlibDecompressor when memory allocation fails with
    MemoryError, which could let a subsequent decompress() call
    read or write through a stale pointer to the
    already-released caller buffer. (bsc#1262098,
    CVE-2026-6100, seems like it has been incompletely applied
    gh#python/cpython#151605)
  - gh-148169: A bypass in webbrowser allowed URLs prefixed
    with %action to pass the dash-prefix safety check
    (bsc#1262098, CVE-2026-6100).
  - gh-146581: Fix vulnerability in shutil.unpack_archive() for
    ZIP files on Windows which allowed to write files outside
    of the destination tree if the patch in the archive
    contains a Windows drive prefix. Now such invalid paths
    will be skipped. Files containing “..” in the name (like
    “foo..bar”) are no longer skipped.
  - gh-146333: Fix quadratic backtracking in
    configparser.RawConfigParser option parsing regexes (OPTCRE
    and OPTCRE_NV). A crafted configuration line with many
    whitespace characters could cause excessive CPU usage.
  - gh-146211: Reject CR/LF characters in tunnel request
    headers for the HTTPConnection.set_tunnel() method.
    (bsc#1261969, CVE-2026-1502)
  - Core and Builtins
  - gh-151112: Fix a crash in the compiler that could occur
    when running out of memory.
  - gh-151126: Fix a crash, when there’s no memory left on
    a device, which happened in:
  - code compilation - _winapi.CreateProcess()
  - Now these places raise proper MemoryError errors.
  - gh-150633: Fix the frozen importer accepting module names
    with embedded null bytes, which caused it to bypass the
    sys.modules cache and create duplicate module objects.
  - gh-149156: Fix an intermittent crash after os.fork() when
    perf trampoline profiling is enabled and the child returns
    through trampoline frames inherited from the parent
    process.
  - gh-149449: Fix a use-after-free crash when the unicodedata
    module was removed from sys.modules and garbage-collected
    between calls that decode \N{...} escapes or use the
    namereplace codec error handler.
  - gh-148450: Fix abc.register() so it invalidates type
    version tags for registered classes.
  - gh-150207: Fix a crash when a memory allocation fails
    during tokenizer initialization. A proper MemoryError is
    now raised instead.
  - gh-150107: asyncio: sendfile() and sock_sendfile() event
    loop methods now call file.seek(offset) if file has
    a seek() method, even if offset is 0 (default value).
  - gh-150146: Fix a crash on a complex type variable
    substitution.
  - from typing import TypeVar;
    memoryview[TypeVar("")][*typing.Mapping[..., ...]] used to
    fail due to missing NULL check on _unpack_args C function
    call.
  - gh-149590: Fix crash when faulthandler is imported more
    than once.
  - gh-149738: sqlite3: Disallow removing row_factory and
    text_factory attributes of a connection to prevent a crash
    on a query.
  - gh-139808: Add branch protections for AArch64 (BTI/PAC) in
    assembly code used by -X perf_jit (Linux perf profiler
    integration).
  - gh-148820: Fix a race in _PyRawMutex on the free-threaded
    build where a Py_PARK_INTR return from _PySemaphore_Wait
    could let the waiter destroy its semaphore before the
    unlocking thread’s _PySemaphore_Wakeup completed, causing
    a fatal ReleaseSemaphore error.
  - gh-148653: Forbid marshalling recursive code objects which
    cannot be correctly unmarshalled.
  - gh-148390: Fix an undefined behavior in memoryview when
    using the native boolean format (?) in cast(). Previously,
    on some common platforms, calling
    memoryview(b).cast("?").tolist() incorrectly returned
    [False] instead of [True] for any even byte b. Patch by
    Bénédikt Tran.
  - gh-148418: Fix a possible reference leak in a corrupted
    TYPE_CODE marshal stream.
  - gh-148222: Fix vectorcall support in types.GenericAlias
    when the underlying type does not support the vectorcall
    protocol. Fix possible leaks in types.GenericAlias and
    types.UnionType in case of memory error.
  - gh-145376: Fix reference leaks in various unusual error
    scenarios.
  - C API
  - gh-150907: Fix dynamic_annotations.h header file when built
    with C++ and Valgrind: add extern "C++" scope for the C++
    template. Patch by Victor Stinner.
  - Build
  - gh-149351: Avoid possible broken macOS framework install
    names when DESTDIR is specified during builds.
  - gh-146475: Block Apple Clang from being used to build the
    JIT as it ships without required LLVM tools.
  - gh-148535: No longer use the gcc -fprofile-update=atomic
    flag on i686. The flag has been added to fix a random GCC
    internal error on PGO build (gh-145801) caused by
    corruption of profile data (.gcda files). The problem is
    that it makes the PGO build way slower (up to 47x slower)
    on i686. Since the GCC internal error was not seen on i686
    so far, don’t use -fprofile-update=atomic on i686 anymore.
    Patch by Victor Stinner.
  - Library
  - gh-150913: Fix sqlite3.Blob slice assignment to raise
    TypeError and IndexError for type and size mismatches
    respectively, even when the target slice is empty.
  - gh-143008: Fix race conditions when re-initializing
    a io.TextIOWrapper object.
  - gh-150685: Update bundled pip to 26.1.2
  - gh-150406: Fix a possible crash occurring during socket
    module initialization when the system is out of memory on
    platforms without a reentrant gethostbyname.
  - gh-150372: readline: Fix a potential crash during tab
    completion caused by an out-of-memory error during module
    initialization.
  - gh-150175: Fix race condition in
    unittest.mock.ThreadingMock where concurrent calls could
    lose increments to call_count and other attributes due to
    a missing lock in _increment_mock_call.
  - gh-84353: Preserve non-UTF-8 encoded filenames when
    appending to a zipfile.ZipFile. Previously, non-ASCII names
    stored in a legacy encoding (without the UTF-8 flag bit
    set) could be corrupted when the central directory was
    rewritten: they were decoded as cp437 and then re-stored as
    UTF-8.
  - gh-149995: Update various docstrings in typing.
  - gh-88726: The email package now uses standard MIME charset
    names “gb2312” and “big5” instead of non-standard names
    “eucgb2312_cn” and “big5_tw”.
  - gh-149571: Fix the C implementation of
    xml.etree.ElementTree.Element.itertext(): it no longer
    emits text for comments and processing instructions.
  - gh-149921: Fix reference leaks in error paths of the
    _interpchannels and _interpqueues extension modules.
  - gh-149801: Add IANA registered names and aliases with
    leading zeros before number (like IBM00858, CP00858,
    IBM01140, CP01140) for corresponding codecs.
  - gh-149701: Fix bad return code from Lib/venv/bin/activate
    if hashing is disabled
  - gh-112821: In the REPL, autocompletion might run arbitrary
    code in the getter of a descriptor. If that getter raised
    an exception, autocompletion would fail to present any
    options for the entire object. Autocompletion now works as
    expected for these objects.
  - gh-149388: Make asyncio.windows_utils.PipeHandle closing
    idempotent.
  - gh-149489: Fix ElementTree serialization to HTML. The
    content of elements “xmp”, “iframe”, “noembed”, “noframes”,
    and “plaintext” is no longer escaped. The “plaintext”
    element no longer have the closing tag.
  - gh-149377: Update bundled pip to 26.1.1
  - gh-149231: In tomllib, the number of parts in TOML keys is
    now limited.
  - gh-149117: Fix runpy.run_module() and runpy.run_path() to
    set the name attribute on the ImportError they raise.
  - gh-149148: ensurepip: Upgrade bundled pip to 26.1. This
    version fixes the CVE 2026-3219 vulnerability. Patch by
    Victor Stinner.
  - gh-148093: Fix an out-of-bounds read of one byte in
    binascii.a2b_uu(). Raise binascii.Error, instead of reading
    past the buffer end.
  - gh-148914: Fix memoization of in-band PickleBuffer in the
    Python implementation of pickle. Previously, identical
    PickleBuffers did not preserve identity, and empty writable
    PickleBuffer memoized an empty bytearray object in place of
    b'', so the following references to b'' were unpickled as
    an empty bytearray object.
  - gh-138907: Support RFC 9309 in urllib.robotparser.
  - gh-148954: Fix XML injection vulnerability in
    xmlrpc.client.dumps() where the methodname was not being
    escaped before interpolation into the XML body.
  - gh-148801: xml.etree.ElementTree: Fix a crash in
    Element.__deepcopy__ on deeply nested trees.
  - gh-148735: xml.etree.ElementTree: Fix a use-after-free in
    Element.findtext when the element tree is mutated
    concurrently during the search.
  - gh-146553: Fix infinite loop in typing.get_type_hints()
    when __wrapped__ forms a cycle. Patch by Shamil Abdulaev.
  - gh-148508: An intermittent timing error when running SSL
    tests on iOS has been resolved.
  - gh-148518: If an email containing an address header that
    ended in an open double quote was parsed with
    a non-compat32 policy, accessing the username attribute of
    the mailbox accessed through that header object would
    result in an IndexError. It now correctly returns an empty
    string as the result.
  - gh-148370: configparser: prevent quadratic behavior when
    a ParsingError is raised after a parser fails to parse
    multiple lines. Patch by Bénédikt Tran.
  - gh-148254: Use singular “sec” instead of “secs” in timeit
    verbose output for consistency with other time units.
  - gh-148192: email.generator.Generator._make_boundary could
    fail to detect a duplicate boundary string if linesep was
    not n. It now correctly detects boundary strings when
    linesep is rn as well.
  - gh-146313: Fix a deadlock in multiprocessing’s resource
    tracker where the parent process could hang indefinitely in
    os.waitpid() during interpreter shutdown if a child created
    via os.fork() still held the resource tracker’s pipe open.
  - gh-145831: Fix email.quoprimime.decode() leaving a stray \r
    when eol='\r\n' by stripping the full eol string instead of
    one character.
  - gh-145105: Fix crash in csv reader when iterating with
    a re-entrant iterator that calls next() on the same reader
    from within __next__.
  - gh-130750: Restore quoting of choices in argparse error
    messages for improved clarity and consistency with
    documentation.
  - gh-105936: Attempting to mutate non-field attributes of
    dataclasses with both frozen and slots being True now
    raises FrozenInstanceError instead of TypeError. Their
    non-dataclass subclasses can now freely mutate non-field
    attributes, and the original non-slotted class can be
    garbage collected. The fix also handles the case of an
    empty __class__ cell on a function found within the class
    (gh-148947).
  - gh-142516: ssl: fix reference leaks in ssl.SSLContext
    objects. Patch by Bénédikt Tran.
  - gh-142831: Fix a crash in the json module where
    a use-after-free could occur if the object being encoded is
    modified during serialization.
  - gh-140287: The asyncio REPL now handles exceptions when
    executing PYTHONSTARTUP scripts. Patch by Bartosz Sławecki.
  - gh-90949: Add
    SetBillionLaughsAttackProtectionActivationThreshold() and
    SetBillionLaughsAttackProtectionMaximumAmplification() to
    xmlparser objects to tune protections against billion
    laughs attacks. Patch by Bénédikt Tran.
  - gh-132631: Fix “I/O operation on closed file” when parsing
    JSON Lines file with JSON CLI.
  - gh-128110: Fix bug in the parsing of email address headers
    that could result in extraneous spaces in the decoded text
    when using a modern email policy. Space between pairs of
    adjacent RFC 2047 encoded-words is now ignored, per section
    6.2 (and consistent with existing parsing of unstructured
    headers like Subject).
  - gh-107398: Fix tarfile stream mode exception when process
    the file with the gzip extra field.
  - gh-123853: Update the table of Windows language code
    identifiers (LCIDs) used by locale.getdefaultlocale() on
    Windows to protocol version 16.0 (2024-04-23).
  - gh-70039: Fixed bug where smtplib.SMTP.starttls() could
    fail if smtplib.SMTP.connect() is called explicitly rather
    than implicitly.
  - gh-83281: email: improve handling trailing garbage in
    address lists to avoid throwing AttributeError in certain
    edge cases
  - gh-91099: imaplib.IMAP4.login() now raises exceptions with
    str instead of bytes. Patch by Florian Best.
  - IDLE
  - bpo-6699: Warn the user if a file will be overwritten when
    saving.
  - Documentation
  - gh-150319: Generic builtin and standard library types now
    document the meaning of their type parameters.
  - gh-148663: Document that calendar.IllegalMonthError is
    a subclass of both ValueError and IndexError since Python
    3.12.
  - gh-146646: Document that glob.glob(), glob.iglob(),
    pathlib.Path.glob(), and pathlib.Path.rglob() silently
    suppress OSError exceptions raised from scanning the
    filesystem.
  - gh-109503: Fix documentation for shutil.move() on usage of
    os.rename() since nonatomic move might be used even if the
    files are on the same filesystem. Patch by Fang Li
  - Tests
  - gh-151130: Add more tests for PyWeakref_* C API.
  - gh-149776: Fix test_socket on Linux kernel 7.1 and newer:
    skip UDP Lite tests if it’s not supported. Patch by Victor
    Stinner.
- Remove upstreamed patches:
  - CVE-2026-1502-reject-CRLF-HTTP-tunnel.patch
  - CVE-2026-4786-webbrowser-open-action.patch
  - CVE-2026-6019-Morsel-js_output.patch
  - CVE-2026-6100-use-after-free-decompression.patch
* Sun Jun 07 2026 mcepl@cepl.eu
- Remove remainders of installation of `python3`-related files.
* Sat Jun 06 2026 mcepl@suse.com
- Keep unversioned Python 3 development entry points in
  python3-devel: python313-devel no longer provides python3-devel
  and no longer owns libpython3.so, python3-config, python3.pc,
  or python3-embed.pc. Do not package versioned GIL pkg-config
  files in nogil-devel. Also, fix regular expressions in
  rpmlintrc.
* Thu Jun 04 2026 mcepl@suse.com
- Add test_UDPLITE_support.patch (bsc#1263787,
  gh#python/cpython!149081) improving testing for the support of
  IPPROTO_UDPLITE, which could be not present although header
  files are.
* Thu Jun 04 2026 mcepl@suse.com
- Add missing BR `crypto-policies-scripts` (need for the fix of
  bsc#1211301).
* Mon Apr 27 2026 mcepl@cepl.eu
- CVE-2026-6019: protect against HTML injection by
  Base64-encoding cookie values embedded in JS (bsc#1262654,
  gh#python/cpython#90309)
  CVE-2026-6019-Morsel-js_output.patch
* Sat Apr 25 2026 mcepl@cepl.eu
- CVE-2026-1502: reject CR/LF in HTTP tunnel request headers
  (bsc#1261969, gh#python/cpython#146211)
  CVE-2026-1502-reject-CRLF-HTTP-tunnel.patch
* Sat Apr 25 2026 mcepl@cepl.eu
- CVE-2026-4786: fix webbrowser %action substitution bypass of
  dash-prefix check (bsc#1262319, gh#python/cpython#148169)
  CVE-2026-4786-webbrowser-open-action.patch
* Fri Apr 24 2026 mcepl@cepl.eu
- CVE-2026-6100: prevent dangling pointer, which can end in the
  use-after-free error (bsc#1262098, gh#python/cpython#148395)
  CVE-2026-6100-use-after-free-decompression.patch
* Wed Apr 08 2026 mcepl@cepl.eu
- Update to 3.13.13
  - Security
  - gh-145986: xml.parsers.expat: Fixed a crash caused by
    unbounded C recursion when converting deeply nested XML
    content models with ElementDeclHandler(). This addresses
    CVE 2026-4224 (bsc#1259735, CVE-2026-4224).
  - gh-145599: Reject control characters in http.cookies.Morsel
    update() and js_output(). This addresses CVE 2026-3644
    (bsc#1259734, CVE-2026-3644).
  - gh-145506: Fixes CVE 2026-2297 by ensuring that
    SourcelessFileLoader uses io.open_code() when opening .pyc
    files (bsc#1259240, CVE-2026-2297).
  - gh-144370: Disallow usage of control characters in status
    in wsgiref.handlers to prevent HTTP header injections.
    Patch by Benedikt Johannes.
  - gh-143930: Reject leading dashes in URLs passed to
    webbrowser.open() (bsc#1260026, CVE-2026-4519).
  - Library
  - gh-144503: Fix a regression introduced in 3.14.3 and
    3.13.12 where the multiprocessing forkserver start method
    would fail with BrokenPipeError when the parent process had
    a very large sys.argv. The argv is now passed to the
    forkserver as separate command-line arguments rather than
    being embedded in the -c command string, avoiding the
    operating system’s per-argument length limit.
  - gh-146613: itertools: Fix a crash in itertools.groupby()
    when the grouper iterator is concurrently mutated.
  - gh-146080: ssl: fix a crash when an SNI callback tries to
    use an SSL object that has already been garbage-collected.
    Patch by Bénédikt Tran.
  - gh-146090: sqlite3: fix a crash when
    sqlite3.Connection.create_collation() fails with
    SQLITE_BUSY. Patch by Bénédikt Tran.
  - gh-146090: sqlite3: properly raise MemoryError instead of
    SystemError when a context callback fails to be allocated.
    Patch by Bénédikt Tran.
  - gh-145633: Fix struct.pack('f', float): use PyFloat_Pack4()
    to raise OverflowError. Patch by Sergey B Kirpichev and
    Victor Stinner.
  - gh-146310: The ensurepip module no longer looks for
    pip-*.whl wheel packages in the current directory.
  - gh-146083: Update bundled libexpat to version 2.7.5.
  - gh-146076: zoneinfo: fix crashes when deleting _weak_cache
    from a zoneinfo.ZoneInfo subclass.
  - gh-146054: Limit the size of encodings.search_function()
    cache. Found by OSS Fuzz in #493449985.
  - gh-145883: zoneinfo: Fix heap buffer overflow reads from
    malformed TZif data. Found by OSS Fuzz, issues #492245058
    and #492230068.
  - gh-145750: Avoid undefined behaviour from signed integer
    overflow when parsing format strings in the struct module.
    Found by OSS Fuzz in #488466741.
  - gh-145492: Fix infinite recursion in
    collections.defaultdict __repr__ when a defaultdict
    contains itself. Based on analysis by KowalskiThomas in
    gh-145492.
  - gh-145623: Fix crash in struct when calling repr() or
    __sizeof__() on an uninitialized struct.Struct object
    created via Struct.__new__() without calling __init__().
  - gh-145616: Detect Android sysconfig ABI correctly on 32-bit
    ARM Android on 64-bit ARM kernel
  - gh-145376: Fix null pointer dereference in unusual error
    scenario in hashlib.
  - gh-145551: Fix InvalidStateError when cancelling process
    created by asyncio.create_subprocess_exec() or
    asyncio.create_subprocess_shell(). Patch by Daan De Meyer.
  - gh-145417: venv: Prevent incorrect preservation of SELinux
    context when copying the Activate.ps1 script. The script
    inherited the SELinux security context of the system
    template directory, rather than the destination project
    directory.
  - gh-145301: hashlib: fix a crash when the initialization of
    the underlying C extension module fails.
  - gh-145264: Base64 decoder (see binascii.a2b_base64(),
    base64.b64decode(), etc) no longer ignores excess data
    after the first padded quad in non-strict (default) mode.
    Instead, in conformance with RFC 4648, section 3.3, it now
    ignores the pad character, “=”, if it is present before the
    end of the encoded data (bsc#1261970, CVE-2026-3446).
  - gh-145158: Avoid undefined behaviour from signed integer
    overflow when parsing format strings in the struct module.
  - gh-144984: Fix crash in
    xml.parsers.expat.xmlparser.ExternalEntityParserCreate()
    when an allocation fails. The error paths could dereference
    NULL handlers and double-decrement the parent parser’s
    reference count.
  - gh-88091: Fix unicodedata.decomposition() for Hangul
    characters.
  - gh-144835: Added missing explanations for some parameters
    in glob.glob() and glob.iglob().
  - gh-144833: Fixed a use-after-free in ssl when SSL_new()
    returns NULL in newPySSLSocket(). The error was reported
    via a dangling pointer after the object had already been
    freed.
  - gh-144259: Fix inconsistent display of long multiline
    pasted content in the REPL.
  - gh-144156: Fix the folding of headers by the email library
    when RFC 2047 encoded words are used. Now whitespace is
    correctly preserved and also correctly added between
    adjacent encoded words. The latter property was broken by
    the fix for gh-92081, which mostly fixed previous failures
    to preserve whitespace.
  - gh-66305: Fixed a hang on Windows in the tempfile module
    when trying to create a temporary file or subdirectory in
    a non-writable directory.
  - gh-140814: multiprocessing.freeze_support() no longer sets
    the default start method as a side effect, which previously
    caused a subsequent multiprocessing.set_start_method() call
    to raise RuntimeError.
  - gh-144475: Calling repr() on functools.partial() is now
    safer when the partial object’s internal attributes are
    replaced while the string representation is being
    generated.
  - gh-144538: Bump the version of pip bundled in ensurepip to
    version 26.0.1
  - gh-144363: Update bundled libexpat to 2.7.4
  - gh-143637: Fixed a crash in socket.sendmsg() that could
    occur if ancillary data is mutated re-entrantly during
    argument parsing.
  - gh-143880: Fix data race in functools.partial() in the free
    threading build.
  - gh-143543: Fix a crash in itertools.groupby that could
    occur when a user-defined __eq__() method re-enters the
    iterator during key comparison.
  - gh-140652: Fix a crash in _interpchannels.list_all() after
    closing a channel.
  - gh-143698: Allow scheduler and setpgroup arguments to be
    explicitly None when calling os.posix_spawn() or
    os.posix_spawnp(). Patch by Bénédikt Tran.
  - gh-143698: Raise TypeError instead of SystemError when the
    scheduler in os.posix_spawn() or os.posix_spawnp() is not
    a tuple. Patch by Bénédikt Tran.
  - gh-143304: Fix ctypes.CDLL to honor the handle parameter on
    POSIX systems.
  - gh-142781: zoneinfo: fix a crash when instantiating
    ZoneInfo objects for which the internal class-level cache
    is inconsistent.
  - gh-142763: Fix a race condition between zoneinfo.ZoneInfo
    creation and zoneinfo.ZoneInfo.clear_cache() that could
    raise KeyError.
  - gh-142787: Fix assertion failure in sqlite3 blob subscript
    when slicing with indices that result in an empty slice.
  - gh-142352: Fix asyncio.StreamWriter.start_tls() to transfer
    buffered data from StreamReader to the SSL layer,
    preventing data loss when upgrading a connection to TLS
    mid-stream (e.g., when implementing PROXY protocol
    support).
  - gh-141707: Don’t change tarfile.TarInfo type from AREGTYPE
    to DIRTYPE when parsing GNU long name or link headers
    (bsc#1259611, CVE-2025-13462).
  - gh-139933: Improve AttributeError suggestions for classes
    with a custom __dir__() method returning a list of
    unsortable values. Patch by Bénédikt Tran.
  - gh-138891: Fix SyntaxError when inspect.get_annotations(f,
    eval_str=True) is called on a function annotated with a PEP
    646 star_expression
  - gh-137335: Get rid of any possibility of a name conflict
    for named pipes in multiprocessing and asyncio on Windows,
    no matter how small.
  - gh-80667: Support lookup for Tangut Ideographs in
    unicodedata.
  - bpo-40243: Fix unicodedata.ucd_3_2_0.numeric() for
    non-decimal values.
  - Documentation
  - gh-126676: Expand argparse documentation for type=bool with
    a demonstration of the surprising behavior and pointers to
    common alternatives.
  - gh-145450: Document missing public wave.Wave_write getter
    methods.
  - Core and Builtins
  - gh-148157: Fix an unlikely crash when parsing an invalid
    type comments for function parameters. Found by OSS Fuzz in
    [#492782951].
  - gh-146615: Fix a crash in __get__() for METH_METHOD
    descriptors when an invalid (non-type) object is passed as
    the second argument. Patch by Steven Sun.
  - gh-146128: Fix a bug which could cause constant values to
    be partially corrupted in AArch64 JIT code. This issue is
    theoretical, and hasn’t actually been observed in
    unmodified Python interpreters.
  - gh-146250: Fixed a memory leak in SyntaxError when
    re-initializing it.
  - gh-146245: Fixed reference leaks in socket when audit hooks
    raise exceptions in socket.getaddrinfo() and
    socket.sendto().
  - gh-146227: Fix wrong type in _Py_atomic_load_uint16 in the
    C11 atomics backend (pyatomic_std.h), which used a 32-bit
    atomic load instead of 16-bit. Found by Mohammed Zuhaib.
  - gh-146056: Fix repr() for lists containing NULLs.
  - gh-145990: python --help-env sections are now sorted by
    environment variable name.
  - gh-145376: Fix GC tracking in structseq.__replace__().
  - gh-142183: Avoid a pathological case where repeated calls
    at a specific stack depth could be significantly slower.
  - gh-145783: Fix an unlikely crash in the parser when certain
    errors were erroneously not propagated. Found by OSS Fuzz
    in #491369109.
  - gh-145701: Fix SystemError when __classdict__ or
    __conditional_annotations__ is in a class-scope inlined
    comprehension. Found by OSS Fuzz in #491105000.
  - gh-145335: Fix a crash in os.pathconf() when called with -1
    as the path argument.
  - gh-145234: Fixed a SystemError in the parser when an
    encoding cookie (for example, UTF-7) decodes to carriage
    returns (\r). Newlines are now normalized after decoding in
    the string tokenizer.
  - Patch by Pablo Galindo.
  - gh-130555: Fix use-after-free in dict.clear() when the
    dictionary values are embedded in an object and
    a destructor causes re-entrant mutation of the dictionary.
  - gh-145008: Fix a bug when calling certain methods at the
    recursion limit which manifested as a corruption of
    Python’s operand stack. Patch by Ken Jin.
  - gh-144872: Fix heap buffer overflow in the parser found by
    OSS-Fuzz.
  - gh-144766: Fix a crash in fork child process when perf
    support is enabled.
  - gh-144759: Fix undefined behavior in the lexer when start
    and multi_line_start pointers are NULL in
    _PyLexer_remember_fstring_buffers() and
    _PyLexer_restore_fstring_buffers(). The NULL pointer
    arithmetic (NULL - valid_pointer) is now guarded with
    explicit NULL checks.
  - gh-144601: Fix crash when importing a module whose PyInit
    function raises an exception from a subinterpreter.
  - gh-143636: Fix a crash when calling
    SimpleNamespace.__replace__() on non-namespace instances.
    Patch by Bénédikt Tran.
  - gh-143650: Fix race condition in importlib where a thread
    could receive a stale module reference when another
    thread’s import fails.
  - gh-140594: Fix an out of bounds read when a single NUL
    character is read from the standard input. Patch by Shamil
    Abdulaev.
  - gh-91636: While performing garbage collection, clear
    weakrefs to unreachable objects that are created during
    running of finalizers. If those weakrefs were are not
    cleared, they could reveal unreachable objects.
  - gh-130327: Fix erroneous clearing of an object’s __dict__
    if overwritten at runtime.
  - gh-80667: Literals using the \N{name} escape syntax can now
    construct CJK ideographs and Hangul syllables using
    case-insensitive names.
  - Build
  - gh-146541: The Android testbed can now be built for 32-bit
    ARM and x86 targets.
  - gh-146450: The Android build script was modified to improve
    parity with other platform build scripts.
  - gh-145801: When Python build is optimized with GCC using
    PGO, use -fprofile-update=atomic option to use atomic
    operations when updating profile information. This option
    reduces the risk of gcov Data Files (.gcda) corruption
    which can cause random GCC crashes. Patch by Victor
    Stinner.
  - gh-129259: Fix AIX build failures caused by incorrect
    struct alignment in _Py_CODEUNIT and _Py_BackoffCounter by
    adding AIX-specific #pragma pack directives.
  - Tests
  - gh-144418: The Android testbed’s emulator RAM has been
    increased from 2 GB to 4 GB.
  - gh-146202: Fix a race condition in regrtest: make sure that
    the temporary directory is created in the worker process.
    Previously, temp_cwd() could fail on Windows if the “build”
    directory was not created. Patch by Victor Stinner.
  - gh-144739: When Python was compiled with system expat older
    then 2.7.2 but tests run with newer expat, still skip
    test.test_pyexpat.MemoryProtectionTest.
- Removed upstreamed patches:
  - CVE-2025-13462-tarinfo-header-parse.patch
  - CVE-2026-2297-SourcelessFileLoader-io_open_code.patch
  - CVE-2026-3479-pkgutil_get_data.patch
  - CVE-2026-3644-cookies-Morsel-update-II.patch
  - CVE-2026-4224-expat-unbound-C-recursion.patch
  - CVE-2026-4519-webbrowser-open-dashes.patch