Skip to content

Commit e6392eb

Browse files
committed
Python 3.11.17
1 parent bdebbf9 commit e6392eb

23 files changed

Lines changed: 182 additions & 71 deletions

‎Doc/library/asyncio-eventloop.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -521,7 +521,7 @@ Opening network connections
521521

522522
Added the *ssl_shutdown_timeout* parameter.
523523

524-
.. versionchanged:: next
524+
.. versionchanged:: 3.11.17
525525
Raises a ``DeprecationWarning`` if ``ssl.check_hostname`` is ``True``
526526
and ``server_hostname`` is not supplied. In Python 3.13 and
527527
later a ``ValueError`` is raised instead.

‎Doc/library/asyncio-stream.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -365,7 +365,7 @@ StreamWriter
365365

366366
.. versionadded:: 3.11
367367

368-
.. versionchanged:: next
368+
.. versionchanged:: 3.11.17
369369
Raises a ``DeprecationWarning`` if ``ssl.check_hostname`` is ``True``
370370
and ``server_hostname`` is not supplied. In Python 3.13 and
371371
later a ``ValueError`` is raised instead.

‎Doc/library/ssl.rst‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1777,7 +1777,7 @@ to speed up repeated connections from the same clients.
17771777

17781778
.. versionadded:: 3.7
17791779

1780-
.. versionchanged:: next
1780+
.. versionchanged:: 3.11.17
17811781
After the callback assigns a new :attr:`SSLSocket.context`, later
17821782
ClientHello messages on the connection are dispatched to the new
17831783
context's *sni_callback*.
@@ -1915,7 +1915,7 @@ to speed up repeated connections from the same clients.
19151915
The method returns an instance of :attr:`SSLContext.sslobject_class`
19161916
instead of hard-coded :class:`SSLObject`.
19171917

1918-
.. versionchanged:: next
1918+
.. versionchanged:: 3.11.17
19191919
The *server_side*, *server_hostname* and *session* parameters are now
19201920
validated as :meth:`SSLContext.wrap_socket` validates them. Previously
19211921
a context with :attr:`~SSLContext.check_hostname` enabled and no

‎Doc/library/tarfile.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1045,7 +1045,7 @@ reused in custom filters:
10451045

10461046
Return the modified ``TarInfo`` member.
10471047

1048-
.. versionchanged:: next
1048+
.. versionchanged:: 3.11.17
10491049

10501050
Filenames containing ``..`` components are now normalized.
10511051

‎Doc/library/urllib.request.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -944,7 +944,7 @@ These methods are available on :class:`HTTPPasswordMgr` and
944944
match authentication URIs with the same scheme or no scheme. A URI without a
945945
scheme matches authentication URIs with any scheme.
946946

947-
.. versionchanged:: next
947+
.. versionchanged:: 3.11.17
948948
Authentication credentials for URIs with a scheme are now scoped by
949949
that scheme.
950950

‎Include/patchlevel.h‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,12 @@
1818
/*--start constants--*/
1919
#define PY_MAJOR_VERSION 3
2020
#define PY_MINOR_VERSION 11
21-
#define PY_MICRO_VERSION 16
21+
#define PY_MICRO_VERSION 17
2222
#define PY_RELEASE_LEVEL PY_RELEASE_LEVEL_FINAL
2323
#define PY_RELEASE_SERIAL 0
2424

2525
/* Version as a string */
26-
#define PY_VERSION "3.11.16+"
26+
#define PY_VERSION "3.11.17"
2727
/*--end constants--*/
2828

2929
/* Version as a single 4-byte hex number, e.g. 0x010502B2 == 1.5.2b2.

‎Lib/pydoc_data/topics.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# -*- coding: utf-8 -*-
2-
# Autogenerated by Sphinx on Thu Aug 13 00:02:25 2026
2+
# Autogenerated by Sphinx on Thu Oct 1 01:48:37 2026
33
# as part of the release process.
44
topics = {'assert': 'The "assert" statement\n'
55
'**********************\n'

‎Misc/NEWS.d/3.11.17.rst‎

Lines changed: 171 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,171 @@
1+
.. date: 2026-09-29-16-32-46
2+
.. gh-issue: 158446
3+
.. nonce: dToaPr
4+
.. release date: 2026-10-01
5+
.. section: Security
6+
7+
Fix a crash or incorrect output that could occur when formatting a
8+
:class:`float` or :class:`complex` with a precision close to the platform's
9+
``INT_MAX``. :c:func:`PyOS_double_to_string` now raises :exc:`ValueError`
10+
for any precision of that magnitude, regardless of presentation type or
11+
value, as the format string parsers already did for precisions above
12+
``INT_MAX``.
13+
14+
..
15+
16+
.. date: 2026-09-23-11-34-30
17+
.. gh-issue: 156793
18+
.. nonce: zC_AjF
19+
.. section: Security
20+
21+
:mod:`asyncio`: :meth:`loop.start_tls() <asyncio.loop.start_tls>` and
22+
:meth:`loop.create_connection() <asyncio.loop.create_connection>` now
23+
validate the *server_hostname* argument if an :class:`ssl.SSLContext` is
24+
passed with *check_hostname* set to ``True``, emitting
25+
:exc:`DeprecationWarning` if *server_hostname* is missing. (This will raise
26+
:exc:`ValueError` in Python 3.13 and later.)
27+
28+
..
29+
30+
.. date: 2026-09-16-14-05-19
31+
.. gh-issue: 156793
32+
.. nonce: Qa1T5Z
33+
.. section: Security
34+
35+
:meth:`ssl.SSLContext.wrap_bio` now validates its *server_side*,
36+
*server_hostname* and *session* arguments similar to
37+
:meth:`ssl.SSLContext.wrap_socket`, but for backward compatiblity reasons
38+
emits :exc:`DeprecationWarning` instead of :exc:`ValueError`.
39+
40+
In particular, a context with :attr:`~ssl.SSLContext.check_hostname` enabled
41+
and no *server_hostname* passed to :meth:`!wrap_bio` now emits
42+
:exc:`DeprecationWarning` to indicate the hostname wasn't checked. (In
43+
Python 3.13 and later, this raises :exc:`ValueError`.)
44+
45+
..
46+
47+
.. date: 2026-09-10-13-38-11
48+
.. gh-issue: 157265
49+
.. nonce: -vYuMp
50+
.. section: Security
51+
52+
In :mod:`tarfile`, when extracting a link falls back to extracting a member
53+
of the archive, skip the member when the filter function returns None when
54+
called with the extracted member's name replaced with the link's.
55+
56+
..
57+
58+
.. date: 2026-09-06-11-02-46
59+
.. gh-issue: 157190
60+
.. nonce: tarhln
61+
.. section: Security
62+
63+
Fixed a vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction
64+
filters where a crafted archive using a hard link to a symbolic link could
65+
change the permissions and modification time of a file outside the
66+
destination directory, and expose its contents inside the extracted tree.
67+
This addresses CVE 2026-82049.
68+
69+
..
70+
71+
.. date: 2026-08-31-16-47-33
72+
.. gh-issue: 157953
73+
.. nonce: KxCF5N
74+
.. section: Security
75+
76+
Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5.
77+
78+
..
79+
80+
.. date: 2026-08-18-13-54-05
81+
.. gh-issue: 156002
82+
.. nonce: CcWXPP
83+
.. section: Security
84+
85+
Bound the amount of data :mod:`zipfile` decompresses per read for members
86+
compressed with bzip2, LZMA, or Zstandard, matching the existing limit for
87+
deflate. A small archive member could previously expand into an unbounded
88+
allocation even when read in small chunks.
89+
90+
..
91+
92+
.. date: 2026-08-13-13-08-11
93+
.. gh-issue: 155999
94+
.. nonce: Xt4rWq
95+
.. section: Security
96+
97+
Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating
98+
directories outside the destination for members whose name leaves the
99+
destination and returns to it, such as ``../evil/../dest/sub/file``. The
100+
containment check used the resolved path, but intermediate directories were
101+
created from the name as given.
102+
103+
..
104+
105+
.. date: 2026-08-10-12-00-00
106+
.. gh-issue: 156293
107+
.. nonce: sNIcbk
108+
.. section: Security
109+
110+
Fix a crash in :mod:`ssl` when an :attr:`~ssl.SSLContext.sni_callback`
111+
switches a connection to another :class:`~ssl.SSLContext` and the context
112+
that carries the callback is no longer referenced by the application.
113+
Servers that keep their ``sni_callback`` context alive (the usual case when
114+
it wraps the listening socket or is stored on the server object) were not
115+
affected. This addresses `CVE-2026-19445
116+
<https://www.cve.org/CVERecord?id=CVE-2026-19445>`_.
117+
118+
..
119+
120+
.. date: 2026-08-06-11-43-20
121+
.. gh-issue: 155292
122+
.. nonce: j4pHBO
123+
.. section: Security
124+
125+
Change the :mod:`stringprep` module and :mod:`encodings.idna` codec to not
126+
consider Unicode codepoint attributes beyond those defined in :rfc:`3454`.
127+
128+
..
129+
130+
.. date: 2026-07-31-16-20-17
131+
.. gh-issue: 155694
132+
.. nonce: SsxlKG
133+
.. section: Security
134+
135+
Fix `CVE-2026-15806 <https://www.cve.org/CVERecord?id=CVE-2026-15806>`_ by
136+
scoping :class:`~urllib.request.HTTPPasswordMgr` credentials to the URL
137+
scheme, preventing credentials stored for an HTTPS URL from being used for a
138+
matching HTTP URL, while URIs without a scheme continue to match any scheme.
139+
140+
..
141+
142+
.. date: 2026-09-08-13-06-29
143+
.. gh-issue: 156002
144+
.. nonce: vmOC8T
145+
.. section: Library
146+
147+
:mod:`zipfile` again reads members through a third-party decompressor
148+
installed by monkey-patching the private ``_get_decompressor()`` to return
149+
an object that only implements old BZ2Decompressor API from Python 3.3. Note
150+
that decompressors without ``needs_input`` and two-argument ``decompress()``
151+
are vulnerable to CVE 2026-15310.
152+
153+
..
154+
155+
.. date: 2026-08-26-02-30-00
156+
.. gh-issue: 156353
157+
.. nonce: abcdef
158+
.. section: Library
159+
160+
Fix :mod:`configparser` parsing when using whitespace in *delimiters*.
161+
162+
..
163+
164+
.. date: 2026-08-13-12-57-27
165+
.. gh-issue: 155757
166+
.. nonce: _5cg0h
167+
.. section: Build
168+
169+
Set the ``--argv0`` argument to wasmtime for WASI builds so the test suite
170+
passes. Otherwise the calculated paths to the stdlib for frozen modules is
171+
incorrect.

‎Misc/NEWS.d/next/Build/2026-08-13-12-57-27.gh-issue-155757._5cg0h.rst‎

Lines changed: 0 additions & 3 deletions
This file was deleted.

‎Misc/NEWS.d/next/Library/2026-08-26-02-30-00.gh-issue-156353.abcdef.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

0 commit comments

Comments
 (0)