<div class="container">
    <h1>Security update for python313, python3</h1>

    <table class="table table-striped table-bordered">
        <tbody>
        <tr>
            <th>Announcement ID:</th>
            <td>SUSE-SU-2026:22959-1</td>
        </tr>
        <tr>
            <th>Release Date:</th>
            <td>2026-07-28T10:31:30Z</td>
        </tr>
        
        <tr>
            <th>Rating:</th>
            <td>important</td>
        </tr>
        <tr>
            <th>References:</th>
            <td>
                <ul>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1211301">bsc#1211301</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1258364">bsc#1258364</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1261969">bsc#1261969</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1261970">bsc#1261970</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262098">bsc#1262098</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262319">bsc#1262319</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262654">bsc#1262654</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1263787">bsc#1263787</a>
                        </li>
                    
                    
                        <li style="display: inline;">
                            <a href="https://jira.suse.com/browse/PED-16123">jsc#PED-16123</a>
                        </li>
                    
                </ul>
            </td>
        </tr>
        
            <tr>
                <th>
                    Cross-References:
                </th>
                <td>
                    <ul>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2021-4189.html">CVE-2021-4189</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-1502.html">CVE-2026-1502</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-3446.html">CVE-2026-3446</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-4786.html">CVE-2026-4786</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-6019.html">CVE-2026-6019</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-6100.html">CVE-2026-6100</a>
                        </li>
                    
                    </ul>
                </td>
            </tr>
            <tr>
                <th>CVSS scores:</th>
                <td>
                    <ul class="list-group">
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2021-4189</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2021-4189</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2021-4189</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-1502</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.7</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-1502</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">4.9</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-1502</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.7</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-3446</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.0</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-3446</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.3</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-3446</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.0</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-4786</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.0</span>
                                <span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-4786</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-4786</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.0</span>
                                <span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-4786</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6019</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">2.1</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6019</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">3.8</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6019</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">2.1</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6019</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">6.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6100</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6100</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6100</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-6100</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</span>
                            </li>
                        
                    </ul>
                </td>
            </tr>
        
        <tr>
            <th>Affected Products:</th>
            <td>
                <ul class="list-group">
                    
                        <li class="list-group-item">SUSE Linux Micro 6.2</li>
                    
                </ul>
            </td>
        </tr>
        </tbody>
    </table>

    <p>An update that solves six vulnerabilities, contains one feature and has two fixes can now be installed.</p>

    


    
        <h2>Description:</h2>
    
    <p>This update for python313, python3 fixes the following issues:</p>
<p>Changes in python313:</p>
<p>Update to 3.13.14:</p>
<ul>
<li>
<p>Security</p>
<ul>
<li>gh-151159: Bumps the OpenSSL version to 3.0.21 on Android.</li>
<li>gh-150599: Fix a possible stack buffer overflow in bz2 when
  a bz2.BZ2Decompressor is reused after a decompression
  error. The decompressor now becomes unusable after libbz2
  reports an error.</li>
<li>gh-149835: shutil.move() now resolves symlinks via
  os.path.realpath() when checking whether the destination is
  inside the source directory, preventing a symlink-based
  bypass of that guard.</li>
<li>gh-149698: Update bundled libexpat to version 2.8.1 for the
  fix for CVE 2026-45186.</li>
<li>gh-87451: The ftplib module’s undocumented ftpcp function
  no longer trusts the IPv4 address value returned from the
  source server in response to the PASV command by default,
  completing the fix for CVE-2021-4189. As with ftplib.FTP,
  the former behavior can be re-enabled by setting the
  trust_server_pasv_ipv4_address attribute on the source
  ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape
  AI for the report.</li>
<li>gh-149486: tarfile.data_filter() now validates link targets
  using the same normalised value that is written to disk,
  strips trailing separators from the member name when
  resolving a symlink’s directory, and rejects link members
  that would replace the destination directory itself. This
  closes several path-traversal bypasses of the data
  extraction filter.</li>
<li>gh-149079: Fix a potential denial of service in
  unicodedata.normalize(). The canonical ordering step of
  Unicode normalization used a quadratic-time insertion sort
  for reordering combining characters, which could be
  exploited with crafted input containing many combining
  characters in non-canonical order. Replaced with
  a linear-time counting sort for long runs.</li>
<li>gh-149018: Improved protection against XML hash-flooding
  attacks in xml.parsers.expat and xml.etree.ElementTree when
  Python is compiled with libExpat 2.8.0 or later.</li>
<li>gh-149017: Update bundled libexpat to version 2.8.0.</li>
<li>gh-90309: Base64-encode values when embedding cookies to
  JavaScript using the http.cookies.BaseCookie.js_output()
  method to avoid injection and escaping. (bsc#1262654,
  CVE-2026-6019)</li>
<li>gh-148808: Added buffer boundary check when using nbytes
  parameter with
  asyncio.AbstractEventLoop.sock_recvfrom_into(). Only
  relevant for Windows and the asyncio.ProactorEventLoop.</li>
<li>gh-148395: Fix a dangling input pointer in
  lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal
  zlib._ZlibDecompressor when memory allocation fails with
  MemoryError, which could let a subsequent decompress() call
  read or write through a stale pointer to the
  already-released caller buffer. (bsc#1262098,
  CVE-2026-6100, seems like it has been incompletely applied
  gh#python/cpython#151605)</li>
<li>gh-148169: A bypass in webbrowser allowed URLs prefixed
  with %action to pass the dash-prefix safety check
  (bsc#1262098, CVE-2026-6100).</li>
<li>gh-146581: Fix vulnerability in shutil.unpack_archive() for
  ZIP files on Windows which allowed to write files outside
  of the destination tree if the patch in the archive
  contains a Windows drive prefix. Now such invalid paths
  will be skipped. Files containing “..” in the name (like
  “foo..bar”) are no longer skipped.</li>
<li>gh-146333: Fix quadratic backtracking in
  configparser.RawConfigParser option parsing regexes (OPTCRE
  and OPTCRE_NV). A crafted configuration line with many
  whitespace characters could cause excessive CPU usage.</li>
<li>gh-146211: Reject CR/LF characters in tunnel request
  headers for the HTTPConnection.set_tunnel() method.
  (bsc#1261969, CVE-2026-1502)</li>
<li>Core and Builtins</li>
<li>gh-151112: Fix a crash in the compiler that could occur
  when running out of memory.</li>
<li>gh-151126: Fix a crash, when there’s no memory left on
  a device, which happened in:</li>
<li>code compilation - _winapi.CreateProcess()</li>
<li>Now these places raise proper MemoryError errors.</li>
<li>gh-150633: Fix the frozen importer accepting module names
  with embedded null bytes, which caused it to bypass the
  sys.modules cache and create duplicate module objects.</li>
<li>gh-149156: Fix an intermittent crash after os.fork() when
  perf trampoline profiling is enabled and the child returns
  through trampoline frames inherited from the parent
  process.</li>
<li>gh-149449: Fix a use-after-free crash when the unicodedata
  module was removed from sys.modules and garbage-collected
  between calls that decode \N{...} escapes or use the
  namereplace codec error handler.</li>
<li>gh-148450: Fix abc.register() so it invalidates type
  version tags for registered classes.</li>
<li>gh-150207: Fix a crash when a memory allocation fails
  during tokenizer initialization. A proper MemoryError is
  now raised instead.</li>
<li>gh-150107: asyncio: sendfile() and sock_sendfile() event
  loop methods now call file.seek(offset) if file has
  a seek() method, even if offset is 0 (default value).</li>
<li>gh-150146: Fix a crash on a complex type variable
  substitution.</li>
<li>from typing import TypeVar;
  memoryview[TypeVar("")][*typing.Mapping[..., ...]] used to
  fail due to missing NULL check on _unpack_args C function
  call.</li>
<li>gh-149590: Fix crash when faulthandler is imported more
  than once.</li>
<li>gh-149738: sqlite3: Disallow removing row_factory and
  text_factory attributes of a connection to prevent a crash
  on a query.</li>
<li>gh-139808: Add branch protections for AArch64 (BTI/PAC) in
  assembly code used by -X perf_jit (Linux perf profiler
  integration).</li>
<li>gh-148820: Fix a race in _PyRawMutex on the free-threaded
  build where a Py_PARK_INTR return from _PySemaphore_Wait
  could let the waiter destroy its semaphore before the
  unlocking thread’s _PySemaphore_Wakeup completed, causing
  a fatal ReleaseSemaphore error.</li>
<li>gh-148653: Forbid marshalling recursive code objects which
  cannot be correctly unmarshalled.</li>
<li>gh-148390: Fix an undefined behavior in memoryview when
  using the native boolean format (?) in cast(). Previously,
  on some common platforms, calling
  memoryview(b).cast("?").tolist() incorrectly returned
  [False] instead of [True] for any even byte b. Patch by
  Bénédikt Tran.</li>
<li>gh-148418: Fix a possible reference leak in a corrupted
  TYPE_CODE marshal stream.</li>
<li>gh-148222: Fix vectorcall support in types.GenericAlias
  when the underlying type does not support the vectorcall
  protocol. Fix possible leaks in types.GenericAlias and
  types.UnionType in case of memory error.</li>
<li>gh-145376: Fix reference leaks in various unusual error
  scenarios.</li>
</ul>
</li>
<li>
<p>C API</p>
<ul>
<li>gh-150907: Fix dynamic_annotations.h header file when built
  with C++ and Valgrind: add extern "C++" scope for the C++
  template. Patch by Victor Stinner.</li>
</ul>
</li>
<li>
<p>Build</p>
<ul>
<li>gh-149351: Avoid possible broken macOS framework install
  names when DESTDIR is specified during builds.</li>
<li>gh-146475: Block Apple Clang from being used to build the
  JIT as it ships without required LLVM tools.</li>
<li>gh-148535: No longer use the gcc -fprofile-update=atomic
  flag on i686. The flag has been added to fix a random GCC
  internal error on PGO build (gh-145801) caused by
  corruption of profile data (.gcda files). The problem is
  that it makes the PGO build way slower (up to 47x slower)
  on i686. Since the GCC internal error was not seen on i686
  so far, don’t use -fprofile-update=atomic on i686 anymore.
  Patch by Victor Stinner.</li>
</ul>
</li>
<li>
<p>Library</p>
<ul>
<li>gh-150913: Fix sqlite3.Blob slice assignment to raise
  TypeError and IndexError for type and size mismatches
  respectively, even when the target slice is empty.</li>
<li>gh-143008: Fix race conditions when re-initializing
  a io.TextIOWrapper object.</li>
<li>gh-150685: Update bundled pip to 26.1.2</li>
<li>gh-150406: Fix a possible crash occurring during socket
  module initialization when the system is out of memory on
  platforms without a reentrant gethostbyname.</li>
<li>gh-150372: readline: Fix a potential crash during tab
  completion caused by an out-of-memory error during module
  initialization.</li>
<li>gh-150175: Fix race condition in
  unittest.mock.ThreadingMock where concurrent calls could
  lose increments to call_count and other attributes due to
  a missing lock in _increment_mock_call.</li>
<li>gh-84353: Preserve non-UTF-8 encoded filenames when
  appending to a zipfile.ZipFile. Previously, non-ASCII names
  stored in a legacy encoding (without the UTF-8 flag bit
  set) could be corrupted when the central directory was
  rewritten: they were decoded as cp437 and then re-stored as
  UTF-8.</li>
<li>gh-149995: Update various docstrings in typing.</li>
<li>gh-88726: The email package now uses standard MIME charset
  names “gb2312” and “big5” instead of non-standard names
  “eucgb2312_cn” and “big5_tw”.</li>
<li>gh-149571: Fix the C implementation of
  xml.etree.ElementTree.Element.itertext(): it no longer
  emits text for comments and processing instructions.</li>
<li>gh-149921: Fix reference leaks in error paths of the
  _interpchannels and _interpqueues extension modules.</li>
<li>gh-149801: Add IANA registered names and aliases with
  leading zeros before number (like IBM00858, CP00858,
  IBM01140, CP01140) for corresponding codecs.</li>
<li>gh-149701: Fix bad return code from Lib/venv/bin/activate
  if hashing is disabled</li>
<li>gh-112821: In the REPL, autocompletion might run arbitrary
  code in the getter of a descriptor. If that getter raised
  an exception, autocompletion would fail to present any
  options for the entire object. Autocompletion now works as
  expected for these objects.</li>
<li>gh-149388: Make asyncio.windows_utils.PipeHandle closing
  idempotent.</li>
<li>gh-149489: Fix ElementTree serialization to HTML. The
  content of elements “xmp”, “iframe”, “noembed”, “noframes”,
  and “plaintext” is no longer escaped. The “plaintext”
  element no longer have the closing tag.</li>
<li>gh-149377: Update bundled pip to 26.1.1</li>
<li>gh-149231: In tomllib, the number of parts in TOML keys is
  now limited.</li>
<li>gh-149117: Fix runpy.run_module() and runpy.run_path() to
  set the name attribute on the ImportError they raise.</li>
<li>gh-149148: ensurepip: Upgrade bundled pip to 26.1. This
  version fixes the CVE 2026-3219 vulnerability. Patch by
  Victor Stinner.</li>
<li>gh-148093: Fix an out-of-bounds read of one byte in
  binascii.a2b_uu(). Raise binascii.Error, instead of reading
  past the buffer end.</li>
<li>gh-148914: Fix memoization of in-band PickleBuffer in the
  Python implementation of pickle. Previously, identical
  PickleBuffers did not preserve identity, and empty writable
  PickleBuffer memoized an empty bytearray object in place of
  b&#x27;&#x27;, so the following references to b&#x27;&#x27; were unpickled as
  an empty bytearray object.</li>
<li>gh-138907: Support RFC 9309 in urllib.robotparser.</li>
<li>gh-148954: Fix XML injection vulnerability in
  xmlrpc.client.dumps() where the methodname was not being
  escaped before interpolation into the XML body.</li>
<li>gh-148801: xml.etree.ElementTree: Fix a crash in
  Element.<strong>deepcopy</strong> on deeply nested trees.</li>
<li>gh-148735: xml.etree.ElementTree: Fix a use-after-free in
  Element.findtext when the element tree is mutated
  concurrently during the search.</li>
<li>gh-146553: Fix infinite loop in typing.get_type_hints()
  when <strong>wrapped</strong> forms a cycle. Patch by Shamil Abdulaev.</li>
<li>gh-148508: An intermittent timing error when running SSL
  tests on iOS has been resolved.</li>
<li>gh-148518: If an email containing an address header that
  ended in an open double quote was parsed with
  a non-compat32 policy, accessing the username attribute of
  the mailbox accessed through that header object would
  result in an IndexError. It now correctly returns an empty
  string as the result.</li>
<li>gh-148370: configparser: prevent quadratic behavior when
  a ParsingError is raised after a parser fails to parse
  multiple lines. Patch by Bénédikt Tran.</li>
<li>gh-148254: Use singular “sec” instead of “secs” in timeit
  verbose output for consistency with other time units.</li>
<li>gh-148192: email.generator.Generator._make_boundary could
  fail to detect a duplicate boundary string if linesep was
  not n. It now correctly detects boundary strings when
  linesep is rn as well.</li>
<li>gh-146313: Fix a deadlock in multiprocessing’s resource
  tracker where the parent process could hang indefinitely in
  os.waitpid() during interpreter shutdown if a child created
  via os.fork() still held the resource tracker’s pipe open.</li>
<li>gh-145831: Fix email.quoprimime.decode() leaving a stray \r
  when eol=&#x27;\r\n&#x27; by stripping the full eol string instead of
  one character.</li>
<li>gh-145105: Fix crash in csv reader when iterating with
  a re-entrant iterator that calls next() on the same reader
  from within <strong>next</strong>.</li>
<li>gh-130750: Restore quoting of choices in argparse error
  messages for improved clarity and consistency with
  documentation.</li>
<li>gh-105936: Attempting to mutate non-field attributes of
  dataclasses with both frozen and slots being True now
  raises FrozenInstanceError instead of TypeError. Their
  non-dataclass subclasses can now freely mutate non-field
  attributes, and the original non-slotted class can be
  garbage collected. The fix also handles the case of an
  empty <strong>class</strong> cell on a function found within the class
  (gh-148947).</li>
<li>gh-142516: ssl: fix reference leaks in ssl.SSLContext
  objects. Patch by Bénédikt Tran.</li>
<li>gh-142831: Fix a crash in the json module where
  a use-after-free could occur if the object being encoded is
  modified during serialization.</li>
<li>gh-140287: The asyncio REPL now handles exceptions when
  executing PYTHONSTARTUP scripts. Patch by Bartosz Sławecki.</li>
<li>gh-90949: Add
  SetBillionLaughsAttackProtectionActivationThreshold() and
  SetBillionLaughsAttackProtectionMaximumAmplification() to
  xmlparser objects to tune protections against billion
  laughs attacks. Patch by Bénédikt Tran.</li>
<li>gh-132631: Fix “I/O operation on closed file” when parsing
  JSON Lines file with JSON CLI.</li>
<li>gh-128110: Fix bug in the parsing of email address headers
  that could result in extraneous spaces in the decoded text
  when using a modern email policy. Space between pairs of
  adjacent RFC 2047 encoded-words is now ignored, per section
  6.2 (and consistent with existing parsing of unstructured
  headers like Subject).</li>
<li>gh-107398: Fix tarfile stream mode exception when process
  the file with the gzip extra field.</li>
<li>gh-123853: Update the table of Windows language code
  identifiers (LCIDs) used by locale.getdefaultlocale() on
  Windows to protocol version 16.0 (2024-04-23).</li>
<li>gh-70039: Fixed bug where smtplib.SMTP.starttls() could
  fail if smtplib.SMTP.connect() is called explicitly rather
  than implicitly.</li>
<li>gh-83281: email: improve handling trailing garbage in
  address lists to avoid throwing AttributeError in certain
  edge cases</li>
<li>gh-91099: imaplib.IMAP4.login() now raises exceptions with
  str instead of bytes. Patch by Florian Best.</li>
<li>IDLE</li>
<li>bpo-6699: Warn the user if a file will be overwritten when
  saving.</li>
<li>Documentation</li>
<li>gh-150319: Generic builtin and standard library types now
  document the meaning of their type parameters.</li>
<li>gh-148663: Document that calendar.IllegalMonthError is
  a subclass of both ValueError and IndexError since Python
  3.12.</li>
<li>gh-146646: Document that glob.glob(), glob.iglob(),
  pathlib.Path.glob(), and pathlib.Path.rglob() silently
  suppress OSError exceptions raised from scanning the
  filesystem.</li>
<li>gh-109503: Fix documentation for shutil.move() on usage of
  os.rename() since nonatomic move might be used even if the
  files are on the same filesystem. Patch by Fang Li</li>
<li>Tests</li>
<li>gh-151130: Add more tests for PyWeakref_* C API.</li>
<li>gh-149776: Fix test_socket on Linux kernel 7.1 and newer:
  skip UDP Lite tests if it’s not supported. Patch by Victor
  Stinner.</li>
</ul>
</li>
<li>
<p>Keep unversioned Python 3 development entry points in
  python3-devel: python313-devel no longer provides python3-devel
  and no longer owns libpython3.so, python3-config, python3.pc,
  or python3-embed.pc. Do not package versioned GIL pkg-config
  files in nogil-devel. Also, fix regular expressions in
  rpmlintrc.</p>
</li>
<li>
<p>Improve testing for the support of IPPROTO_UDPLITE, which could be
  not present although header files are. (bsc#1263787,
  gh#python/cpython!149081)</p>
</li>
<li>
<p>Add missing BR <code>crypto-policies-scripts</code> (need for the fix of
  bsc#1211301).</p>
</li>
<li>
<p>CVE-2026-6019: protect against HTML injection by
  Base64-encoding cookie values embedded in JS (bsc#1262654,
  gh#python/cpython#90309)</p>
</li>
<li>
<p>CVE-2026-1502: reject CR/LF in HTTP tunnel request headers
  (bsc#1261969, gh#python/cpython#146211)</p>
</li>
<li>
<p>CVE-2026-4786: fix webbrowser %action substitution bypass of
  dash-prefix check (bsc#1262319, gh#python/cpython#148169)</p>
</li>
<li>
<p>CVE-2026-6100: prevent dangling pointer, which can end in the
  use-after-free error (bsc#1262098, gh#python/cpython#148395)</p>
</li>
</ul>
<p>Changes in python3:</p>
<ul>
<li>Provide explicitly also file dependencies /usr/bin/python3 and
  /usr/bin/pydoc3.</li>
</ul>
<p>break bootstrap build dependency cycle on primary python</p>
<p>Break the cyclic build dependency loop between <code>python3</code> and
<code>python313</code> during version upgrades (such as 3.13.13 to 3.13.14).</p>
<p>Previously, <code>python3.spec</code> required <code>BuildRequires:
%{primary_python}</code> (the versioned non-base interpreter package)
and queried its version via <code>rpm -q</code> during spec file parsing.
During upgrades, this blocked the build of <code>python3</code> because
<code>%{primary_python}</code> (non-base) depended on <code>python3-base</code>, which
demanded the new <code>python313-base</code> version.</p>
<p>Since the unversioned compatibility package <code>python3</code> only
creates unversioned symlinks (like <code>/usr/bin/python3</code>) and owns
generic RPM macros, it does not actually require the versioned
standard library modules (the non-base flavor) to build.</p>
<p>This change allows <code>python3</code> to build successfully against the
already built <code>python313-base</code> and <code>python313-devel</code> packages,
breaking the circular dependency and enabling a clean upgrade
path.</p>
<ul>
<li>
<p>Let python3-devel explicitly provide pkgconfig(python3) and
  pkgconfig(python3-embed), matching its ownership of the unversioned
  pkg-config files.</p>
</li>
<li>
<p>Complete the transition of the unversioned python3 namespace
  (jsc#PED-16123, bsc#1258364).</p>
</li>
<li>Add missing Provides/Obsoletes for generic names.</li>
<li>
<p>Add macros.python3 (moved from python313).</p>
</li>
<li>
<p>Add BuildIgnore: gdb
  BuildRequires: python313-devel → python313-devel owns
  /usr/share/gdb/auto-load/...libpython3.13...-gdb.py → the
  currently published version of that file has #!/usr/bin/python3
  → RPM auto-generated Requires: python3-base on gdb → OBS tries
  to install gdb into the build root and fails because
  python3-base is the package being built.</p>
</li>
<li>Correct the logic in the %pre scripts.</li>
<li>
<p>version of the package must be equal to the version of
  %primary_python</p>
</li>
<li>
<p>Initial packaging effort for the python3 superpackage.</p>
</li>
</ul>
<p>python3 is shipped as new package.</p>



    

    <h2>Patch Instructions:</h2>
    <p>
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".<br/>

        Alternatively you can run the command listed for your product:
    </p>
    <ul class="list-group">
        
            <li class="list-group-item">
                SUSE Linux Micro 6.2
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SL-Micro-6.2-1359=1</code>
                    
                    
                
            </li>
        
    </ul>

    <h2>Package List:</h2>
    <ul>
        
            
                <li>
                    SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64)
                    <ul>
                        
                            <li>python313-base-debuginfo-3.13.14-160000.1.1</li>
                        
                            <li>python3-3.13.14-160000.1.1</li>
                        
                            <li>python313-curses-debuginfo-3.13.14-160000.1.1</li>
                        
                            <li>python313-3.13.14-160000.1.1</li>
                        
                            <li>libpython3_13-1_0-debuginfo-3.13.14-160000.1.1</li>
                        
                            <li>python313-core-debugsource-3.13.14-160000.1.1</li>
                        
                            <li>python313-debuginfo-3.13.14-160000.1.1</li>
                        
                            <li>python3-curses-3.13.14-160000.1.1</li>
                        
                            <li>python313-debugsource-3.13.14-160000.1.1</li>
                        
                            <li>python3-base-3.13.14-160000.1.1</li>
                        
                            <li>python313-base-3.13.14-160000.1.1</li>
                        
                            <li>python313-curses-3.13.14-160000.1.1</li>
                        
                            <li>libpython3_13-1_0-3.13.14-160000.1.1</li>
                        
                    </ul>
                </li>
            
        
    </ul>

    
        <h2>References:</h2>
        <ul>
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2021-4189.html">https://www.suse.com/security/cve/CVE-2021-4189.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-1502.html">https://www.suse.com/security/cve/CVE-2026-1502.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-3446.html">https://www.suse.com/security/cve/CVE-2026-3446.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-4786.html">https://www.suse.com/security/cve/CVE-2026-4786.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-6019.html">https://www.suse.com/security/cve/CVE-2026-6019.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-6100.html">https://www.suse.com/security/cve/CVE-2026-6100.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1211301">https://bugzilla.suse.com/show_bug.cgi?id=1211301</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1258364">https://bugzilla.suse.com/show_bug.cgi?id=1258364</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1261969">https://bugzilla.suse.com/show_bug.cgi?id=1261969</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1261970">https://bugzilla.suse.com/show_bug.cgi?id=1261970</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262098">https://bugzilla.suse.com/show_bug.cgi?id=1262098</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262319">https://bugzilla.suse.com/show_bug.cgi?id=1262319</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262654">https://bugzilla.suse.com/show_bug.cgi?id=1262654</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1263787">https://bugzilla.suse.com/show_bug.cgi?id=1263787</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://jira.suse.com/browse/PED-16123">https://jira.suse.com/browse/PED-16123</a>
                    </li>
                
            
        </ul>
    
</div>