Skip to content

Commit e848e4b

Browse files
committed
Python 3.12.15
1 parent 869069d commit e848e4b

23 files changed

Lines changed: 181 additions & 71 deletions

‎Doc/library/asyncio-eventloop.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -544,7 +544,7 @@ Opening network connections
544544
.. versionchanged:: 3.12
545545
*all_errors* was added.
546546

547-
.. versionchanged:: next
547+
.. versionchanged:: 3.12.15
548548
Raises a ``DeprecationWarning`` if ``ssl.check_hostname`` is ``True``
549549
and ``server_hostname`` is not supplied. In Python 3.13 and
550550
later a ``ValueError`` is raised instead.

‎Doc/library/asyncio-stream.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -382,7 +382,7 @@ StreamWriter
382382
.. versionchanged:: 3.12
383383
Added the *ssl_shutdown_timeout* parameter.
384384

385-
.. versionchanged:: next
385+
.. versionchanged:: 3.12.15
386386
Raises a ``DeprecationWarning`` if ``ssl.check_hostname`` is ``True``
387387
and ``server_hostname`` is not supplied. In Python 3.13 and
388388
later a ``ValueError`` is raised instead.

‎Doc/library/ssl.rst‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1695,7 +1695,7 @@ to speed up repeated connections from the same clients.
16951695

16961696
.. versionadded:: 3.7
16971697

1698-
.. versionchanged:: next
1698+
.. versionchanged:: 3.12.15
16991699
After the callback assigns a new :attr:`SSLSocket.context`, later
17001700
ClientHello messages on the connection are dispatched to the new
17011701
context's *sni_callback*.
@@ -1833,7 +1833,7 @@ to speed up repeated connections from the same clients.
18331833
The method returns an instance of :attr:`SSLContext.sslobject_class`
18341834
instead of hard-coded :class:`SSLObject`.
18351835

1836-
.. versionchanged:: next
1836+
.. versionchanged:: 3.12.15
18371837
The *server_side*, *server_hostname* and *session* parameters are now
18381838
validated as :meth:`SSLContext.wrap_socket` validates them. Previously
18391839
a context with :attr:`~SSLContext.check_hostname` enabled and no

‎Doc/library/tarfile.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1047,7 +1047,7 @@ reused in custom filters:
10471047

10481048
Return the modified ``TarInfo`` member.
10491049

1050-
.. versionchanged:: next
1050+
.. versionchanged:: 3.12.15
10511051

10521052
Filenames containing ``..`` components are now normalized.
10531053

‎Doc/library/urllib.request.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -956,7 +956,7 @@ These methods are available on :class:`HTTPPasswordMgr` and
956956
match authentication URIs with the same scheme or no scheme. A URI without a
957957
scheme matches authentication URIs with any scheme.
958958

959-
.. versionchanged:: next
959+
.. versionchanged:: 3.12.15
960960
Authentication credentials for URIs with a scheme are now scoped by
961961
that scheme.
962962

‎Include/patchlevel.h‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,12 @@
1818
/*--start constants--*/
1919
#define PY_MAJOR_VERSION 3
2020
#define PY_MINOR_VERSION 12
21-
#define PY_MICRO_VERSION 14
21+
#define PY_MICRO_VERSION 15
2222
#define PY_RELEASE_LEVEL PY_RELEASE_LEVEL_FINAL
2323
#define PY_RELEASE_SERIAL 0
2424

2525
/* Version as a string */
26-
#define PY_VERSION "3.12.14+"
26+
#define PY_VERSION "3.12.15"
2727
/*--end constants--*/
2828

2929
/* Version as a single 4-byte hex number, e.g. 0x010502B2 == 1.5.2b2.

‎Lib/pydoc_data/topics.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Autogenerated by Sphinx on Wed Aug 12 15:57:50 2026
1+
# Autogenerated by Sphinx on Thu Oct 1 00:04:15 2026
22
# as part of the release process.
33

44
topics = {

‎Misc/NEWS.d/3.12.15.rst‎

Lines changed: 170 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,170 @@
1+
.. date: 2026-09-29-16-32-46
2+
.. gh-issue: 158446
3+
.. nonce: dToaPr
4+
.. release date: 2026-10-01
5+
.. section: Security
6+
7+
Fix a crash or incorrect output that could occur when formatting a
8+
:class:`float` or :class:`complex` with a precision close to the platform's
9+
``INT_MAX``. :c:func:`PyOS_double_to_string` now raises :exc:`ValueError`
10+
for any precision of that magnitude, regardless of presentation type or
11+
value, as the format string parsers already did for precisions above
12+
``INT_MAX``.
13+
14+
..
15+
16+
.. date: 2026-09-23-11-34-30
17+
.. gh-issue: 156793
18+
.. nonce: zC_AjF
19+
.. section: Security
20+
21+
:mod:`asyncio`: :meth:`loop.start_tls() <asyncio.loop.start_tls>` and
22+
:meth:`loop.create_connection() <asyncio.loop.create_connection>` now
23+
validate the *server_hostname* argument if an :class:`ssl.SSLContext` is
24+
passed with *check_hostname* set to ``True``, emitting
25+
:exc:`DeprecationWarning` if *server_hostname* is missing. (This will raise
26+
:exc:`ValueError` in Python 3.13 and later.)
27+
28+
..
29+
30+
.. date: 2026-09-16-14-05-19
31+
.. gh-issue: 156793
32+
.. nonce: Qa1T5Z
33+
.. section: Security
34+
35+
:meth:`ssl.SSLContext.wrap_bio` now validates its *server_side*,
36+
*server_hostname* and *session* arguments similar to
37+
:meth:`ssl.SSLContext.wrap_socket`, but for backward compatiblity reasons
38+
emits :exc:`DeprecationWarning` instead of :exc:`ValueError`.
39+
40+
In particular, a context with :attr:`~ssl.SSLContext.check_hostname` enabled
41+
and no *server_hostname* passed to :meth:`!wrap_bio` now emits
42+
:exc:`DeprecationWarning` to indicate the hostname wasn't checked. (In
43+
Python 3.13 and later, this raises :exc:`ValueError`.)
44+
45+
..
46+
47+
.. date: 2026-09-10-13-38-11
48+
.. gh-issue: 157265
49+
.. nonce: -vYuMp
50+
.. section: Security
51+
52+
In :mod:`tarfile`, when extracting a link falls back to extracting a member
53+
of the archive, skip the member when the filter function returns None when
54+
called with the extracted member's name replaced with the link's.
55+
56+
..
57+
58+
.. date: 2026-09-06-11-02-46
59+
.. gh-issue: 157190
60+
.. nonce: tarhln
61+
.. section: Security
62+
63+
Fixed a vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction
64+
filters where a crafted archive using a hard link to a symbolic link could
65+
change the permissions and modification time of a file outside the
66+
destination directory, and expose its contents inside the extracted tree.
67+
This addresses :cve:`2026-82049`.
68+
69+
..
70+
71+
.. date: 2026-08-31-16-47-33
72+
.. gh-issue: 157953
73+
.. nonce: KxCF5N
74+
.. section: Security
75+
76+
Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5.
77+
78+
..
79+
80+
.. date: 2026-08-18-13-54-05
81+
.. gh-issue: 156002
82+
.. nonce: CcWXPP
83+
.. section: Security
84+
85+
Bound the amount of data :mod:`zipfile` decompresses per read for members
86+
compressed with bzip2, LZMA, or Zstandard, matching the existing limit for
87+
deflate. A small archive member could previously expand into an unbounded
88+
allocation even when read in small chunks.
89+
90+
..
91+
92+
.. date: 2026-08-13-13-08-11
93+
.. gh-issue: 155999
94+
.. nonce: Xt4rWq
95+
.. section: Security
96+
97+
Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating
98+
directories outside the destination for members whose name leaves the
99+
destination and returns to it, such as ``../evil/../dest/sub/file``. The
100+
containment check used the resolved path, but intermediate directories were
101+
created from the name as given.
102+
103+
..
104+
105+
.. date: 2026-08-10-12-00-00
106+
.. gh-issue: 156293
107+
.. nonce: sNIcbk
108+
.. section: Security
109+
110+
Fix a crash in :mod:`ssl` when an :attr:`~ssl.SSLContext.sni_callback`
111+
switches a connection to another :class:`~ssl.SSLContext` and the context
112+
that carries the callback is no longer referenced by the application.
113+
Servers that keep their ``sni_callback`` context alive (the usual case when
114+
it wraps the listening socket or is stored on the server object) were not
115+
affected. This addresses :cve:`2026-19445`.
116+
117+
..
118+
119+
.. date: 2026-08-06-11-43-20
120+
.. gh-issue: 155292
121+
.. nonce: j4pHBO
122+
.. section: Security
123+
124+
Change the :mod:`stringprep` module and :mod:`encodings.idna` codec to not
125+
consider Unicode codepoint attributes beyond those defined in :rfc:`3454`.
126+
127+
..
128+
129+
.. date: 2026-07-31-16-20-17
130+
.. gh-issue: 155694
131+
.. nonce: SsxlKG
132+
.. section: Security
133+
134+
Fix :cve:`2026-15806` by scoping :class:`~urllib.request.HTTPPasswordMgr`
135+
credentials to the URL scheme, preventing credentials stored for an HTTPS
136+
URL from being used for a matching HTTP URL, while URIs without a scheme
137+
continue to match any scheme.
138+
139+
..
140+
141+
.. date: 2026-09-08-13-06-29
142+
.. gh-issue: 156002
143+
.. nonce: vmOC8T
144+
.. section: Library
145+
146+
:mod:`zipfile` again reads members through a third-party decompressor
147+
installed by monkey-patching the private ``_get_decompressor()`` to return
148+
an object that only implements old BZ2Decompressor API from Python 3.3. Note
149+
that decompressors without ``needs_input`` and two-argument ``decompress()``
150+
are vulnerable to :cve:`2026-15310`.
151+
152+
..
153+
154+
.. date: 2026-08-26-02-30-00
155+
.. gh-issue: 156353
156+
.. nonce: abcdef
157+
.. section: Library
158+
159+
Fix :mod:`configparser` parsing when using whitespace in *delimiters*.
160+
161+
..
162+
163+
.. date: 2026-08-13-12-57-27
164+
.. gh-issue: 155757
165+
.. nonce: _5cg0h
166+
.. section: Build
167+
168+
Set the ``--argv0`` argument to wasmtime for WASI builds so the test suite
169+
passes. Otherwise the calculated paths to the stdlib for frozen modules is
170+
incorrect.

‎Misc/NEWS.d/next/Build/2026-08-13-12-57-27.gh-issue-155757._5cg0h.rst‎

Lines changed: 0 additions & 3 deletions
This file was deleted.

‎Misc/NEWS.d/next/Library/2026-08-26-02-30-00.gh-issue-156353.abcdef.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

0 commit comments

Comments
 (0)