#1138157 Python 3.13 memory leak

Package:
python3.13
Source:
python3.13
Description:
Interactive high-level object-oriented language (version 3.13)
Submitter:
Kurt Roeckx
Date:
2026-07-19 17:23:01 UTC
Severity:
normal
#1138157#5
Date:
2026-05-28 12:31:57 UTC
From:
To:
Hi,

It seems there is a memory leak in python. The upstream fix was committed a few days ago:
https://github.com/python/cpython/pull/148371

Can we get a fix for that in stable?

Kurt

#1138157#10
Date:
2026-06-11 02:35:48 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python3.13, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138157@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Stefano Rivera <stefanor@debian.org> (supplier of updated python3.13 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 10 Jun 2026 14:10:12 -0400
Source: python3.13
Architecture: source
Version: 3.13.14-1
Distribution: unstable
Urgency: medium
Maintainer: Matthias Klose <doko@debian.org>
Changed-By: Stefano Rivera <stefanor@debian.org>
Closes: 1101810 1109449 1138157
Changes:
 python3.13 (3.13.14-1) unstable; urgency=medium
 .
   * Python 3.13.14.
     - Avoid crash decompressing untrusted bz2 data. CVE-2026-9669.
     - Don't trust server-provided passive connection addresses in ftplib.
       CVE-2026-8328.
     - Don't allow untrusted tarfile extraction to write outside the
       destination. CVE-2026-7774.
     - Protects against DoS in expat XML parsing. CVE-2026-7210.
     - Avoid use-after-free in decompressors under memory pressure.
       CVE-2026-6100.
     - Base64-encode cookie values embedded in JS. CVE-2026-6019.
     - Protect webbrowser %action substitutions. CVE-2026-4786.
     - Avoid DoS in unicode normalization. CVE-2026-3276.
     - Reject CR/LF in HTTP tunnel request headers. CVE-2026-1502.
     - Fixes reference leaks in ssl.Context. Closes: #1138157.
   * Python 3.13.13 resolved some security issues:
     - Avoid launching webbrowser with attacker controlled options.
       CVE-2026-4519.
     - Avoid C stack overflow in Expat parsing with registered
       ElementDeclHandler. CVE-2026-4224.
     - Reject control characters in Morsel cookies. CVE-2026-3644.
     - Base64 decode no longer ignores data after the first padded quad.
       CVE-2026-3446.
     - Ensure io.open_code is used to read .pyc files. CVE-2026-2297.
     - Skip TarInfo DIRTYPE normalization during GNU long name handling.
       CVE-2025-13462.
 .
   [ Matthias Klose ]
   * Explicitly build-depend on uuid-dev. LP: #2147343.
 .
   [ Colin Watson ]
   * Drop libnsl-dev build-dependency, which is superfluous since the nis
     module was removed in Python 3.13.
 .
   [ Stefano Rivera ]
   * Refresh patches.
   * Drop mention of gdbinit from README.debug. Closes: #1109449.
   * Tidy up python3.X-config manpage. Closes: #1101810.
Checksums-Sha1:
 2c8220840437c8d34a9a8063557d19a6c3b09df9 3697 python3.13_3.13.14-1.dsc
 2c448ef334b33b3a2db9bbc70b9b51b312e1cc32 23021880 python3.13_3.13.14.orig.tar.xz
 5bf5920ac08e02093c783995d216a721fdef4dbc 963 python3.13_3.13.14.orig.tar.xz.asc
 4b88ee232b124eb4f879f1ff4d203fdf5ff1cca3 261180 python3.13_3.13.14-1.debian.tar.xz
 8b01e1fb0cf68ca9b8546ce34363b6dddd07de52 9583 python3.13_3.13.14-1_source.buildinfo
Checksums-Sha256:
 03a7b347861b7e56bae6895f6d0d2f3f4101a5e7d7a247d36ef166eabe17cb75 3697 python3.13_3.13.14-1.dsc
 639e43243c620a308f968213df9e00f2f8f62332f7adbaa7a7eeb9783057c690 23021880 python3.13_3.13.14.orig.tar.xz
 81335bb62d1321ae78a4c70ebeb33007e126df3510cebe1f6e2b4b5e6adf5414 963 python3.13_3.13.14.orig.tar.xz.asc
 cadcb15e1b585c0109a4d3807806d9e02178f0e80fdc8a733b0c836cf2a29bb9 261180 python3.13_3.13.14-1.debian.tar.xz
 f88f1f328fa752e48d8930d9a9dd70c3aff03506cfabe1a6cd5ecb3203a367c4 9583 python3.13_3.13.14-1_source.buildinfo
Files:
 d0059d89959d79f4d17a824ddc5c60a7 3697 python optional python3.13_3.13.14-1.dsc
 b080786b09a61ab277632259b9031d3f 23021880 python optional python3.13_3.13.14.orig.tar.xz
 d2281a8871f8a5b563fc03e544516e15 963 python optional python3.13_3.13.14.orig.tar.xz.asc
 f989966b75711da1b2b226a8d3cea4a4 261180 python optional python3.13_3.13.14-1.debian.tar.xz
 2d3003f2c823a678db654020114b2bf5 9583 python optional python3.13_3.13.14-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iIoEARYKADIWIQTumtb5BSD6EfafSCRHew2wJjpU2AUCaioYDxQcc3RlZmFub3JA
ZGViaWFuLm9yZwAKCRBHew2wJjpU2NFWAQCgAQW/YK3oVgojFq1myHnnV/YuylTb
HFsugI2VXaibNgD/cwJ3DY8nX0DdyLnXrQ/krBbyGoAbGyHgfaiNUx3xGwI=
=KpCp
-----END PGP SIGNATURE-----

#1138157#15
Date:
2026-06-16 11:43:58 UTC
From:
To:
Are there plans to fix this in stable?

Kurt

#1138157#20
Date:
2026-06-16 16:43:03 UTC
From:
To:
Hi Kurt (2026.06.16_11:43:58_+0000)

Yes, in #1139577

Stefano

#1138157#25
Date:
2026-07-04 17:17:06 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python3.13, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138157@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Stefano Rivera <stefanor@debian.org> (supplier of updated python3.13 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 13 Jun 2026 10:18:01 -0400
Source: python3.13
Architecture: source
Version: 3.13.5-2+deb13u3
Distribution: trixie
Urgency: medium
Maintainer: Matthias Klose <doko@debian.org>
Changed-By: Stefano Rivera <stefanor@debian.org>
Closes: 1108039 1138157
Changes:
 python3.13 (3.13.5-2+deb13u3) trixie; urgency=medium
 .
   [ Stefano Rivera ]
   * Patches:
     - Fix a crash in SNI callback when the SSL object is gone.
     - Fix reference leaks in ssl.SSLContext objects. (Closes: #1138157)
     - Avoid garbage collecting objects too early when sharing __dict__
       (Closes: #1108039)
     - Update the patch for CVE-2026-6019 to use decodeURIComponent.
 .
   [ Moritz Mühlenhoff ]
   * CVE-2026-1502
   * CVE-2026-3276
   * CVE-2026-7774
   * CVE-2026-8328
   * CVE-2026-9669
Checksums-Sha1:
 04defc6b604f4324962dffe506f1d8ffcd8c1e1d 3721 python3.13_3.13.5-2+deb13u3.dsc
 11afa083b71c9f1b5e03a35ba0a7a7525f9255ca 295440 python3.13_3.13.5-2+deb13u3.debian.tar.xz
 a289325ba76f9b89be35137214e1dc59ff8198fe 9914 python3.13_3.13.5-2+deb13u3_source.buildinfo
Checksums-Sha256:
 2f6c3f83cd3de0355f4411807871a95f99a0aae9b397daba5dbdbf1bd5169cc8 3721 python3.13_3.13.5-2+deb13u3.dsc
 8e9ed35b583e093f80fbcd53bf3de9245c8070cc5ea9b36e5f34d3a45bff73e9 295440 python3.13_3.13.5-2+deb13u3.debian.tar.xz
 dd4e76440279d5275e2661dad7e2657ce5b7c05f1164235a3361d16fda7f824e 9914 python3.13_3.13.5-2+deb13u3_source.buildinfo
Files:
 7a825a024e6be72b2d096daf406f0312 3721 python optional python3.13_3.13.5-2+deb13u3.dsc
 d83b9e9c7ba756c6a2b3a8369d7bbbd5 295440 python optional python3.13_3.13.5-2+deb13u3.debian.tar.xz
 955bf77430750e4ce1c003b11239940f 9914 python optional python3.13_3.13.5-2+deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iIoEARYKADIWIQTumtb5BSD6EfafSCRHew2wJjpU2AUCai1myxQcc3RlZmFub3JA
ZGViaWFuLm9yZwAKCRBHew2wJjpU2AAFAQC/F3JT85w/cv6uDk751KeuNCyReRNY
QlgvM6qnf0RDWAEAtEsiiy6Qh1nU40oAxt3nouclvdjzC+Ex3530ULUFjAM=
=nhAp
-----END PGP SIGNATURE-----

#1138157#30
Date:
2026-07-19 17:12:36 UTC
From:
To:
reopen 1138157
thanks

Still seeing it with 3.13.5-2+deb13u3 and 3.13.5-2+deb13u4


Kurt