stable

python3.14-3.14.4-2.fc44

FEDORA-2026-841a2250e4 created by churchyard a month ago for Fedora 44

Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-5713, CVE-2026-6100

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-841a2250e4

This update has been submitted for testing by churchyard.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'passed'.

a month ago

This update has been pushed to testing.

a month ago
User Icon filiperosset commented & provided feedback a month ago
karma

no regressions noted

User Icon bojan commented & provided feedback a month ago
karma

Works.

This update can be pushed to stable now if the maintainer wishes

a month ago
User Icon ankursinha commented & provided feedback a month ago
karma

No issues noted

User Icon derekenz commented & provided feedback a month ago
karma

Works

no issues detected

karma

This update has been submitted for stable by bodhi.

There is an ongoing freeze; this will be pushed to stable after the freeze is over.

a month ago
User Icon kparal commented & provided feedback a month ago
karma

Workstation usage is fine

This update has been pushed to stable.

a month ago
User Icon decathorpe commented & provided feedback a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
6
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
5
Stable by Time
14 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago
BZ#2457944 CVE-2026-1502 python3.14: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
0
0
BZ#2458016 CVE-2026-6100 python3.14: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules [fedora-all]
0
0
BZ#2458224 CVE-2026-4786 python3.14: Python: Arbitrary code execution via command injection in webbrowser.open() API [fedora-all]
0
0
BZ#2458488 CVE-2026-5713 python3.14: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
0
0

Automated Test Results