From 06d1a726740da3f064aa067556c18700cac1dfb54acd4d18e2b86c1140aeb87d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mat=C4=9Bj=20Cepl?= Date: Tue, 11 Nov 2025 22:21:05 +0100 Subject: [PATCH] Mark the upgrade to 3.11.14 as fixing CVE-2025-8291, bsc#1251305. --- python311.changes | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/python311.changes b/python311.changes index 5c5eef1..32ae292 100644 --- a/python311.changes +++ b/python311.changes @@ -5,7 +5,8 @@ Wed Oct 15 08:52:35 UTC 2025 - Daniel Garcia - Security - gh-139700: Check consistency of the zip64 end of central directory record. Support records with “zip64 extensible data” - if there are no bytes prepended to the ZIP file. + if there are no bytes prepended to the ZIP file + (CVE-2025-8291, bsc#1251305). - gh-139400: xml.parsers.expat: Make sure that parent Expat parsers are only garbage-collected once they are no longer referenced by subparsers created by