SUSE-CU-2026:8762-1: Security update of bci/python
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Aug 15 07:36:48 UTC 2026
SUSE Container Update Advisory: bci/python
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8762-1
Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.31
Container Release : 85.31
Severity : important
Type : security
References : 1264962 1265268 1267581 1267821 1268375 1268977 1269066 1269788
1269959 1271192 1273090 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972
CVE-2026-13346 CVE-2026-15308 CVE-2026-3276 CVE-2026-4360 CVE-2026-7210
CVE-2026-7774 CVE-2026-8328
-----------------------------------------------------------------
The container bci/python was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3560-1
Released: Mon Aug 10 20:09:08 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328
This update for python311 fixes the following issues:
Security issues fixed:
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
`configparser` module is used (bsc#1269066).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted
Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
hardlinks (bsc#1269959).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding
protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory
(bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
(bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
(bsc#1271192).
Non security issue fixed:
- [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3589-1
Released: Tue Aug 11 16:57:03 2026
Summary: Security update for python-pip
Type: security
Severity: moderate
References: 1273090,CVE-2026-13346
This update for python-pip fixes the following issue:
- CVE-2026-13346: incorrect handling of doubly-encoded package URLs from malicious indexes allows files to be installed
to arbitrary locations on disk (bsc#1273090).
The following package changes have been done:
- libpython3_11-1_0-3.11.15-150600.3.62.2 updated
- python311-base-3.11.15-150600.3.62.2 updated
- python311-pip-22.3.1-150400.17.29.1 updated
- python311-3.11.15-150600.3.62.2 updated
- python311-devel-3.11.15-150600.3.62.2 updated
More information about the sle-container-updates
mailing list