SUSE-CU-2026:7881-1: Security update of bci/python

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Aug 4 13:53:00 UTC 2026


SUSE Container Update Advisory: bci/python
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7881-1
Container Tags        : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.18
Container Release     : 85.18
Severity              : important
Type                  : security
References            : 1261969 1262098 1262319 1262654 1263656 1263658 CVE-2026-1502
                        CVE-2026-4786 CVE-2026-5435 CVE-2026-6019 CVE-2026-6100 CVE-2026-6238
-----------------------------------------------------------------

The container bci/python was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released:    Wed Jul 15 11:53:06 2026
Summary:     Security update for glibc
Type:        security
Severity:    moderate
References:  1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues

- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
  (bsc#1263658).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3104-1
Released:    Fri Jul 17 15:31:14 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100
This update for python311 fixes the following issues

- CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969).
- CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the
  `webbrowser.open()` API (bsc#1262319).
- CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654).
- CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the
  decompression instance is re-used (bsc#1262098).


The following package changes have been done:

- glibc-2.38-150600.14.52.1 updated
- libpython3_11-1_0-3.11.15-150600.3.59.3 updated
- python311-base-3.11.15-150600.3.59.3 updated
- python311-3.11.15-150600.3.59.3 updated
- python311-devel-3.11.15-150600.3.59.3 updated
- container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated


More information about the sle-container-updates mailing list