{"id":2224317,"url":"http://patchwork.ozlabs.org/api/1.2/patches/2224317/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/patch/20260417091800.2374733-1-titouan.christophe@mind.be/","project":{"id":27,"url":"http://patchwork.ozlabs.org/api/1.2/projects/27/?format=json","name":"Buildroot development","link_name":"buildroot","list_id":"buildroot.buildroot.org","list_email":"buildroot@buildroot.org","web_url":"","scm_url":"","webscm_url":"","list_archive_url":"","list_archive_url_format":"","commit_url_format":""},"msgid":"<20260417091800.2374733-1-titouan.christophe@mind.be>","list_archive_url":null,"date":"2026-04-17T09:18:00","name":"[for,2025.02.x] package/python3: security bump to v3.12.13","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"aad879ec75d03dd3efab5a5ff5b817e443e3714f","submitter":{"id":90763,"url":"http://patchwork.ozlabs.org/api/1.2/people/90763/?format=json","name":"Titouan Christophe","email":"titouan.christophe@mind.be"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/buildroot/patch/20260417091800.2374733-1-titouan.christophe@mind.be/mbox/","series":[{"id":500287,"url":"http://patchwork.ozlabs.org/api/1.2/series/500287/?format=json","web_url":"http://patchwork.ozlabs.org/project/buildroot/list/?series=500287","date":"2026-04-17T09:18:00","name":"[for,2025.02.x] package/python3: security bump to v3.12.13","version":1,"mbox":"http://patchwork.ozlabs.org/series/500287/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2224317/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2224317/checks/","tags":{},"related":[],"headers":{"Return-Path":"<buildroot-bounces@buildroot.org>","X-Original-To":["incoming-buildroot@patchwork.ozlabs.org","buildroot@buildroot.org"],"Delivered-To":["patchwork-incoming-buildroot@legolas.ozlabs.org","buildroot@buildroot.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=buildroot.org header.i=@buildroot.org\n header.a=rsa-sha256 header.s=default header.b=W6hB4zUL;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=buildroot.org\n (client-ip=2605:bc80:3010::136; helo=smtp3.osuosl.org;\n envelope-from=buildroot-bounces@buildroot.org; receiver=patchwork.ozlabs.org)"],"Received":["from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fxq743PQNz1yD3\n\tfor <incoming-buildroot@patchwork.ozlabs.org>;\n Fri, 17 Apr 2026 19:18:24 +1000 (AEST)","from localhost (localhost [127.0.0.1])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id AF51F60D71;\n\tFri, 17 Apr 2026 09:18:22 +0000 (UTC)","from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id YNbAHzbiwyyN; Fri, 17 Apr 2026 09:18:21 +0000 (UTC)","from lists1.osuosl.org (lists1.osuosl.org [140.211.166.142])\n\tby smtp3.osuosl.org (Postfix) with ESMTP id C852760D61;\n\tFri, 17 Apr 2026 09:18:21 +0000 (UTC)","from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136])\n by lists1.osuosl.org (Postfix) with ESMTP id 1942C259\n for <buildroot@buildroot.org>; Fri, 17 Apr 2026 09:18:20 +0000 (UTC)","from localhost (localhost [127.0.0.1])\n by smtp3.osuosl.org (Postfix) with ESMTP id 099EA60D61\n for <buildroot@buildroot.org>; Fri, 17 Apr 2026 09:18:20 +0000 (UTC)","from smtp3.osuosl.org ([127.0.0.1])\n by localhost (smtp3.osuosl.org [127.0.0.1]) (amavis, port 10024) with ESMTP\n id CKmOvXc_mxFR for <buildroot@buildroot.org>;\n Fri, 17 Apr 2026 09:18:19 +0000 (UTC)","from mail-ej1-x632.google.com (mail-ej1-x632.google.com\n [IPv6:2a00:1450:4864:20::632])\n by smtp3.osuosl.org (Postfix) with ESMTPS id D02CB60D4D\n for <buildroot@buildroot.org>; Fri, 17 Apr 2026 09:18:18 +0000 (UTC)","by mail-ej1-x632.google.com with SMTP id\n a640c23a62f3a-b8f9568e074so86467466b.0\n for <buildroot@buildroot.org>; Fri, 17 Apr 2026 02:18:18 -0700 (PDT)","from dragon.home ([109.136.97.112]) by smtp.gmail.com with ESMTPSA\n id\n a640c23a62f3a-ba455045898sm35055366b.48.2026.04.17.02.18.15\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Fri, 17 Apr 2026 02:18:15 -0700 (PDT)"],"X-Virus-Scanned":["amavis at osuosl.org","amavis at osuosl.org"],"X-Comment":"SPF check N/A for local connections - client-ip=140.211.166.142;\n helo=lists1.osuosl.org; envelope-from=buildroot-bounces@buildroot.org;\n receiver=<UNKNOWN> ","DKIM-Filter":["OpenDKIM Filter v2.11.0 smtp3.osuosl.org C852760D61","OpenDKIM Filter v2.11.0 smtp3.osuosl.org D02CB60D4D"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=buildroot.org;\n\ts=default; t=1776417501;\n\tbh=7R+wDjCVcoqB2kw2k0eZqM/BvfWtY3lcvmji0H3gi70=;\n\th=To:Date:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post:\n\t List-Help:List-Subscribe:From:Reply-To:Cc:From;\n\tb=W6hB4zULGt3VWsa2LLB1uDryF1f/avUiefDuu0l8Pg2CR3AlRFwWfm1rdoWmcSgWF\n\t qjuYtvSBA/FCyxTGl2GLuTB9AR40CAd5rpPmaQisEpyo6tVu4iQQccbHgquFuetBca\n\t qcnyzhQMaElKzQgUnZ5IkkfV0r0fM/0e2y0xifrWRP+wL493FphcwsRYHO+tVkfd4g\n\t bonDaCtec8cwryMoDZPgGykZS7fAQ2szOnoq573Wl8mJr8zEejfEcMBSTkiUXXGXDT\n\t T1AMwP/g6TCYlL9WvRoFfP1xkfOn/8pzJ7TR0wKeZgef8IA15XwkYpT4vpjJMzKvcB\n\t WxhmNTVStNSdA==","Received-SPF":"Pass (mailfrom) identity=mailfrom;\n client-ip=2a00:1450:4864:20::632; helo=mail-ej1-x632.google.com;\n envelope-from=titouan.christophe@essensium.com; receiver=<UNKNOWN>","DMARC-Filter":"OpenDMARC Filter v1.4.2 smtp3.osuosl.org D02CB60D4D","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1776417496; x=1777022296;\n h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date\n :message-id:reply-to;\n bh=euuDkA+3jIX9z16MqYQuW+CqMec5yrEASzW/8njZ3/g=;\n b=JMj9yrLOCmz1Mq9ZrMPJdSVgLQrO0Rqm4jtVxA/q/+5UNFdDP1uTxaqiPVJO4o6fHt\n 6VAVlbOOtwlfowCXmu+6u/HT6dc8R0bTsqMatPaGVVjZy/YYpMWPyFuCKr4OkoarZoqi\n ImGKtU39zFw+LFpVqZwmu3ZZAYYb7S8k1rXGqZtiJ6rmHQMYBntUP2gA6pYMSLIsXiDA\n +J/ixVOATBZZcmWhTTRvYXRW2Jzf90nWPLc9I/8Gg6B24XZq9a35deEuzEE+NEfb+aNY\n UBihyGOp5VMNzrgk8eroIKzLbl4nTs1mRElpLNptXgmhoa7BJYSo144YKvPl643PTvAV\n 1jDg==","X-Gm-Message-State":"AOJu0YwchYwJcpnj0F+ZVrcoUx5ji2F2JY5EYlQg2tdjqnLeYe2ouvsj\n s2qnSbRa1vNcBGcMZ6zjvZBgI0gE3dbcymx/t489rNMA168hUPcrmzGCRONMX0cJcjnvcEOhatv\n fi5MNtxg=","X-Gm-Gg":"AeBDietL1qA6DUolF8Sg4Tu020IjiFpvG8EgKHqW4jLoQWLsBv7yIFiSe8J87KfsN15\n sFoJpRjBNxQIJLKRiMa7fvBemD9AylNsd/OtKH56ch0LEZSFFNbJ4Jaw2fls8N+TDiDb88wb1Ok\n VpBYpJryDLEmxe8+AGMrLTLjfrqCn2NjrqPF/bKSYyyatotC9EAzp/Sxe/KX7PzaSFM/ZUBc8iY\n bExzqwcPtgtN/QLpMlaZApjoaDLv1YhGhZK5/3TI9L0JCm+q8N9yYVfEPxOXZVVvis8qBtPuX57\n u+Qxf4KI57Z/na1A2Y6+ikNh/pWs6FRkyIDtTWZljeTyukQ8cv+QNur0+uc24j8oAt3JaQJ8tcn\n 4nE0MID3s8BPg0a5ltiGyfT6Y5kUlwHQ0tjxS312W3omAzZU5TRn/pJNHTNu70mCVKdtjoeEOe8\n cVfPwkBCCEhQi714UhXsYzLolQce9TwMdOfCPodKGffY571kCZVUnEpw==","X-Received":"by 2002:a17:907:960b:b0:b9d:68c5:81cc with SMTP id\n a640c23a62f3a-ba41adfa30bmr107031466b.33.1776417496114;\n Fri, 17 Apr 2026 02:18:16 -0700 (PDT)","To":"buildroot@buildroot.org","Date":"Fri, 17 Apr 2026 11:18:00 +0200","Message-ID":"<20260417091800.2374733-1-titouan.christophe@mind.be>","X-Mailer":"git-send-email 2.53.0","MIME-Version":"1.0","X-Mailman-Original-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=mind.be; s=google; t=1776417496; x=1777022296; darn=buildroot.org;\n h=content-transfer-encoding:mime-version:message-id:date:subject:cc\n :to:from:from:to:cc:subject:date:message-id:reply-to;\n bh=euuDkA+3jIX9z16MqYQuW+CqMec5yrEASzW/8njZ3/g=;\n b=WvgIImiFTxpI+Q08Y7TFMA0AFsknzPBb3Pld3eVCCBeMXnisCnT1OpJSIzQffvEEBF\n K0Hs8dPrcW+b2iRl9hzd1gKuk4pHv61ox6D06RtP1pS8QH99uXD9q3tLfYxZfss31/EZ\n D3J8VXbY+u4QoFgENonRg8DiWn6V3tTdXcImj14ZhhL1e3K8WQksQu0EaYBE6CxHuEYt\n 3Lsw6pzLwNHpmIf/CfWDL0JT+76/qgJv59VzVjXNXcwCz3Lh4EcS5XaZXPCVXhNBTjnh\n fsHVmE0RHYB2Rfzrtn1Qb24ohktfspVCxgycUGhP0auomvt6kPhu0bX01Vu1Y2ibPTgt\n SaYw==","X-Mailman-Original-Authentication-Results":["smtp3.osuosl.org;\n dmarc=pass (p=quarantine dis=none)\n header.from=mind.be","smtp3.osuosl.org;\n dkim=pass (2048-bit key,\n unprotected) header.d=mind.be header.i=@mind.be header.a=rsa-sha256\n header.s=google header.b=WvgIImiF"],"Subject":"[Buildroot] [PATCH for 2025.02.x] package/python3: security bump to\n v3.12.13","X-BeenThere":"buildroot@buildroot.org","X-Mailman-Version":"2.1.30","Precedence":"list","List-Id":"Discussion and development of buildroot <buildroot.buildroot.org>","List-Unsubscribe":"<https://lists.buildroot.org/mailman/options/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=unsubscribe>","List-Archive":"<http://lists.buildroot.org/pipermail/buildroot/>","List-Post":"<mailto:buildroot@buildroot.org>","List-Help":"<mailto:buildroot-request@buildroot.org?subject=help>","List-Subscribe":"<https://lists.buildroot.org/mailman/listinfo/buildroot>,\n <mailto:buildroot-request@buildroot.org?subject=subscribe>","From":"Titouan Christophe via buildroot <buildroot@buildroot.org>","Reply-To":"Titouan Christophe <titouan.christophe@mind.be>","Cc":"James Hilliard <james.hilliard1@gmail.com>, thomas.perale@mind.be,\n Thomas Petazzoni <thomas.petazzoni@bootlin.com>","Content-Type":"text/plain; charset=\"utf-8\"","Content-Transfer-Encoding":"base64","Errors-To":"buildroot-bounces@buildroot.org","Sender":"\"buildroot\" <buildroot-bounces@buildroot.org>"},"content":"See the release notes: https://www.python.org/downloads/release/python-31213/\n\nThis fixes a handful of bugs and the following vulnerability:\n- CVE-2024-6923:\n    There is a MEDIUM severity vulnerability affecting CPython.  The\n    email module didn’t properly quote newlines for email headers when\n    serializing an email message allowing for header injection when an\n    email  is serialized.\n    https://www.cve.org/CVERecord?id=CVE-2024-6923\n\nThis also includes a mitigation for a libexpat vulnerability:\n- CVE-2025-59375:\n    libexpat in Expat before 2.7.2 allows attackers to trigger large\n    dynamic memory allocations via a small document that is submitted for\n    parsing.\n    https://www.cve.org/CVERecord?id=CVE-2025-59375\n\nSigned-off-by: Titouan Christophe <titouan.christophe@mind.be>\n---\n package/python3/python3.hash | 6 +++---\n package/python3/python3.mk   | 2 +-\n 2 files changed, 4 insertions(+), 4 deletions(-)","diff":"diff --git a/package/python3/python3.hash b/package/python3/python3.hash\nindex ed0d879f11..5b10f24f70 100644\n--- a/package/python3/python3.hash\n+++ b/package/python3/python3.hash\n@@ -1,5 +1,5 @@\n-# From https://www.python.org/downloads/release/python-31211/\n-md5  04feb01316c7bb1b448001adbc63dd23  Python-3.12.12.tar.xz\n+# From https://www.python.org/downloads/release/python-31213/\n+md5  b67dc5d55b27c98a36615f7d0dfa6e4c  Python-3.12.13.tar.xz\n # Locally computed\n-sha256  fb85a13414b028c49ba18bbd523c2d055a30b56b18b92ce454ea2c51edc656c4  Python-3.12.12.tar.xz\n+sha256  c08bc65a81971c1dd5783182826503369466c7e67374d1646519adf05207b684  Python-3.12.13.tar.xz\n sha256  3b2f81fe21d181c499c59a256c8e1968455d6689d269aa85373bfb6af41da3bf  LICENSE\ndiff --git a/package/python3/python3.mk b/package/python3/python3.mk\nindex 4ace4d8573..60ab5b0cbc 100644\n--- a/package/python3/python3.mk\n+++ b/package/python3/python3.mk\n@@ -5,7 +5,7 @@\n ################################################################################\n \n PYTHON3_VERSION_MAJOR = 3.12\n-PYTHON3_VERSION = $(PYTHON3_VERSION_MAJOR).12\n+PYTHON3_VERSION = $(PYTHON3_VERSION_MAJOR).13\n PYTHON3_SOURCE = Python-$(PYTHON3_VERSION).tar.xz\n PYTHON3_SITE = https://python.org/ftp/python/$(PYTHON3_VERSION)\n PYTHON3_LICENSE = Python-2.0, others\n","prefixes":["for","2025.02.x"]}