-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 08 Apr 2026 08:58:00 +0700 Source: python3.11 Binary: libpython3.11 libpython3.11-dbg libpython3.11-dev libpython3.11-minimal libpython3.11-stdlib python3.11 python3.11-dbg python3.11-dev python3.11-full python3.11-minimal python3.11-nopie python3.11-venv Architecture: ppc64el Version: 3.11.2-6+deb12u7 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Arnaud Rebillout Description: libpython3.11 - Shared Python runtime library (version 3.11) libpython3.11-dbg - Debug Build of the Python Interpreter (version 3.11) libpython3.11-dev - Header files and a static library for Python (v3.11) libpython3.11-minimal - Minimal subset of the Python language (version 3.11) libpython3.11-stdlib - Interactive high-level object-oriented language (standard library python3.11 - Interactive high-level object-oriented language (version 3.11) python3.11-dbg - Debug Build of the Python Interpreter (version 3.11) python3.11-dev - Header files and a static library for Python (v3.11) python3.11-full - Python Interpreter with complete class library (version 3.11) python3.11-minimal - Minimal subset of the Python language (version 3.11) python3.11-nopie - Python interpreter linked without PIE (version 3.11) python3.11-venv - Interactive high-level object-oriented language (pyvenv binary, v Changes: python3.11 (3.11.2-6+deb12u7) bookworm; urgency=medium . * Non-maintainer upload. * Apply upstream patches for the following CVEs: - CVE-2025-4516: issue in bytes.decode("unicode_escape", error="ignore|replace") - CVE-2025-6069: quadratic complexity in html.parser.HTMLParser - CVE-2025-6075: performance degradation in os.path.expandvars() - CVE-2025-8194: infinite loop and deadlock in tarfile - CVE-2025-8291: incorrect ZIP64 End of Central Directory handling - CVE-2025-11468: Folding email comments of unfoldable characters didn't preserve parenthesis which could be abused. - CVE-2025-12084: quadratic complexity in xml.dom.minidom appendChild etc - CVE-2025-13836: OOM or other DoS due to incorrect Content-Length handling in http.client - CVE-2025-13837: OOM or other DoS due to incorrect data size handling in plistlib - CVE-2025-15282: User-controlled data URLs parsed by urllib allowed injecting headers through newlines in the data URL mediatype. - CVE-2026-0672: User-controlled cookie values and parameters could be used to inject HTTP headers into messages. - CVE-2026-0865: User-controlled header names and values containing newlines could be used to inject HTTP headers. - CVE-2026-1299: email module allowed header injection in the BytesGenerator class. Checksums-Sha1: a1e382629900edcb49e7cfbff11884ae46ce1ba4 17154568 libpython3.11-dbg_3.11.2-6+deb12u7_ppc64el.deb 9ea00515f42e95ef5216c4ebb64ac9755c4e5184 4955328 libpython3.11-dev_3.11.2-6+deb12u7_ppc64el.deb e7295e212f4a6e20c967f6f8903137d8cb06a520 816092 libpython3.11-minimal_3.11.2-6+deb12u7_ppc64el.deb 8a465532374befeabf0b909604df4fac00f7f56e 1812432 libpython3.11-stdlib_3.11.2-6+deb12u7_ppc64el.deb 4ec789a33523d592d62d3df6ed015bf68c51b615 2083448 libpython3.11_3.11.2-6+deb12u7_ppc64el.deb f5a25bf72db2a8309c10cfe3408bc25414ab880c 37349264 python3.11-dbg_3.11.2-6+deb12u7_ppc64el.deb 4d8209efba2396ca8a7da23b736c2c24b14f7b14 617696 python3.11-dev_3.11.2-6+deb12u7_ppc64el.deb 1d4b88fdfa234f20f8c153c0e62916ad2ca89e7f 1292 python3.11-full_3.11.2-6+deb12u7_ppc64el.deb 06124d42d796ab0c1ca3b6f88d1be2bb3d2a8eb5 2076136 python3.11-minimal_3.11.2-6+deb12u7_ppc64el.deb 941aa1346d30fb3d1608666a828ce20805b7d497 2066900 python3.11-nopie_3.11.2-6+deb12u7_ppc64el.deb c1127c09d2b750870aa7414e06735568d5aaf154 5892 python3.11-venv_3.11.2-6+deb12u7_ppc64el.deb 8fe3b88a2b002d007202d6a0fb87f4ea950e300f 13650 python3.11_3.11.2-6+deb12u7_ppc64el-buildd.buildinfo 9a560b23dd540fa3b607701f97127afb6d2be295 573820 python3.11_3.11.2-6+deb12u7_ppc64el.deb Checksums-Sha256: 03508a96544f3977c926245ad305251e6c562d8a4dfdc83d1aa1f164a3528566 17154568 libpython3.11-dbg_3.11.2-6+deb12u7_ppc64el.deb 4de05ffdd022659314c2be451776e4b0cc9080b389203b9a751cf15c54f76e13 4955328 libpython3.11-dev_3.11.2-6+deb12u7_ppc64el.deb 9e07356666f693f6aa04b3aa5d93f55e833aad179fb726522bf71b7b51d33ec8 816092 libpython3.11-minimal_3.11.2-6+deb12u7_ppc64el.deb 04e27e71cb9b6dea9b65e47c4feade2fdf9b685d5ec53d1ced27b6f9ec6a8a1a 1812432 libpython3.11-stdlib_3.11.2-6+deb12u7_ppc64el.deb fec88ffa75a3e1ea913c73dd91bc7b3950ae4635f134297fafb1e6e441e0f804 2083448 libpython3.11_3.11.2-6+deb12u7_ppc64el.deb 8b0e26676aa89829a788cf0afed57481df3b649292531c7260ba8e46261b9b8e 37349264 python3.11-dbg_3.11.2-6+deb12u7_ppc64el.deb f293dd01d3a8a73ef1a1c1dbb6964026a7b79cb4c02f2b25d5fabc2c32311531 617696 python3.11-dev_3.11.2-6+deb12u7_ppc64el.deb dbf6297bccb20f6d262ae137f1ad3dce5f98c4dfe67dd47b9404183e18544d2a 1292 python3.11-full_3.11.2-6+deb12u7_ppc64el.deb 82624c79986846c184b6055d8fed1ea4834716fc66273ae59ab8148024047615 2076136 python3.11-minimal_3.11.2-6+deb12u7_ppc64el.deb 67ddb4352bdbab89e7d0bb409ba691ee364139f7df270041431a60f32ed2bc17 2066900 python3.11-nopie_3.11.2-6+deb12u7_ppc64el.deb 12f48137dd886706da5f13d67766c4ed14e220fe33cae3b12322a73fba08e264 5892 python3.11-venv_3.11.2-6+deb12u7_ppc64el.deb e2c7258c8e9be45f62cc3c1d6d3038d93bc62c3db63b395b8e4957680548575b 13650 python3.11_3.11.2-6+deb12u7_ppc64el-buildd.buildinfo 4274eeb6c1f146c48eae8396b54e77ad49f74cd8a1acc2777d47f6f9a5a28401 573820 python3.11_3.11.2-6+deb12u7_ppc64el.deb Files: e28c678c7ef15670688bd41fd17f20b5 17154568 debug optional libpython3.11-dbg_3.11.2-6+deb12u7_ppc64el.deb ffab90d4d98f8a6f17d16d830da660ba 4955328 libdevel optional libpython3.11-dev_3.11.2-6+deb12u7_ppc64el.deb 7b7ad69a1ea59273a618951e27eb0d98 816092 python optional libpython3.11-minimal_3.11.2-6+deb12u7_ppc64el.deb bd4c1422669053dfde299e92628a4cbc 1812432 python optional libpython3.11-stdlib_3.11.2-6+deb12u7_ppc64el.deb 59419e0496e4189e5a92691f3c1cb911 2083448 libs optional libpython3.11_3.11.2-6+deb12u7_ppc64el.deb 4df9b7e7624a7beca9eafe1219d53735 37349264 debug optional python3.11-dbg_3.11.2-6+deb12u7_ppc64el.deb 1ce7471dd2d69d62fb2b8dd01d944e40 617696 python optional python3.11-dev_3.11.2-6+deb12u7_ppc64el.deb 388f4b4bbaba3e0d5feb2e6875109732 1292 python optional python3.11-full_3.11.2-6+deb12u7_ppc64el.deb d0c2078d314cb4e6025aa3243d5340fa 2076136 python optional python3.11-minimal_3.11.2-6+deb12u7_ppc64el.deb 71b6881667364c5b0e2a25e831f55d73 2066900 python optional python3.11-nopie_3.11.2-6+deb12u7_ppc64el.deb b3429bb9f65bae0046de1c5abe31016f 5892 python optional python3.11-venv_3.11.2-6+deb12u7_ppc64el.deb 698560b19fbe6d57f5a326d550993583 13650 python optional python3.11_3.11.2-6+deb12u7_ppc64el-buildd.buildinfo 51e58025f6e53db09b8b933e0d1ca5d3 573820 python optional python3.11_3.11.2-6+deb12u7_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYo4fOZBRi9qmvTxH1PowSTJ8+YQFAmn2uw4ACgkQ1PowSTJ8 +YSzbRAAr4guSRrmSmngLRwtpkO0W9tc3jtaeI0f9UgiE8IqMiXorBI9rtCXD4DA yzdMdQ5fQh9PJMWGESrXNFCuYj7Qi1uhm1BPOsL4RAAPmhEKnCkbEeO1W6Atg0U3 hYIq+WQ8n/rvTx53DV47T1W39oxZFRkSgWdozfKRm1OgkNq/keJEFMA0EUipZMsa FTOPigbVqxnW8FRhdaEkHjqVKu1smTgdVh6MJEoyZx5Cyu9vnBbcrHPvleumgQ8l fdxM0T8CmJJUwluUsO6pbts1pRT0Cv4dPYAdhnUnFmx4IhixFwAntwo6ZLw3uusk JRCkvAHt4/Jv+pf9IsxCsv252/SdaYxEj9L2jnT1rAxBpCAA5QLOcEKobupjj5ix svdp8s9TNEbPkYrEtc9PVR0WF0f6j5hXlDOitG1oTeYVppScpdtMxydwtBYBgzcC 53aGIwHuvO/UZfqIEAtvB8f0XkHG2xl2G3XJjOqsPW0j8M6o11KbCGUIHUhDCZGY ncAIsWW/RSPChGgu+I7rGZl21dgJW8DAAuBBuewfH4lyq/igFHvTdcPGnH0dzvk3 e3rlUytFu503zLYybyE72DLUNmML0VTR1KZVmgUiRSdZJ56MxoMCLmSr/Npx5YNE 1rn0X51f1uXVAVg9DoJYBNfbkG5ZDNVc7Ayqcr03AvF4d0YJxk0= =PdwW -----END PGP SIGNATURE-----