SUSE-CU-2026:8765-1: Security update of bci/python

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Aug 15 07:39:02 UTC 2026


SUSE Container Update Advisory: bci/python
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8765-1
Container Tags        : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.27
Container Release     : 84.27
Severity              : moderate
Type                  : security
References            : 1271712 1273090 CVE-2026-13346 
-----------------------------------------------------------------

The container bci/python was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3578-1
Released:    Tue Aug 11 15:58:41 2026
Summary:     Security update for openssl-1_1
Type:        security
Severity:    moderate
References:  1271712
This update for openssl-1_1 fixes the following issues:

- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
  (bsc#1271712).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3588-1
Released:    Tue Aug 11 16:56:34 2026
Summary:     Security update for python3-pip
Type:        security
Severity:    moderate
References:  1273090,CVE-2026-13346
This update for python3-pip fixes the following issue:

- CVE-2026-13346: incorrect handling of doubly-encoded package URLs from malicious indexes allows files to be installed
  to arbitrary locations on disk (bsc#1273090).


The following package changes have been done:

- libopenssl1_1-1.1.1w-150700.11.25.2 updated
- python3-pip-20.0.2-150400.26.1 updated


More information about the sle-container-updates mailing list