SUSE-CU-2026:7881-1: Security update of bci/python
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Tue Aug 4 13:53:00 UTC 2026
SUSE Container Update Advisory: bci/python
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7881-1
Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.18
Container Release : 85.18
Severity : important
Type : security
References : 1261969 1262098 1262319 1262654 1263656 1263658 CVE-2026-1502
CVE-2026-4786 CVE-2026-5435 CVE-2026-6019 CVE-2026-6100 CVE-2026-6238
-----------------------------------------------------------------
The container bci/python was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3104-1
Released: Fri Jul 17 15:31:14 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100
This update for python311 fixes the following issues
- CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969).
- CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the
`webbrowser.open()` API (bsc#1262319).
- CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654).
- CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the
decompression instance is re-used (bsc#1262098).
The following package changes have been done:
- glibc-2.38-150600.14.52.1 updated
- libpython3_11-1_0-3.11.15-150600.3.59.3 updated
- python311-base-3.11.15-150600.3.59.3 updated
- python311-3.11.15-150600.3.59.3 updated
- python311-devel-3.11.15-150600.3.59.3 updated
- container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated
More information about the sle-container-updates
mailing list