SUSE-CU-2026:8904-1: Security update of suse/sl-micro/6.0/toolbox
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Aug 19 07:42:56 UTC 2026
SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8904-1
Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.151 , suse/sl-micro/6.0/toolbox:latest
Container Release : 9.151
Severity : important
Type : security
References : 1258364 1261969 1262098 1262319 1262654 1263083 1264962 1265268
1267581 1267821 1268375 1268977 1269066 1269788 1269959 1271192
CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-1502 CVE-2026-15308
CVE-2026-3276 CVE-2026-4360 CVE-2026-4786 CVE-2026-6019 CVE-2026-6100
CVE-2026-7210 CVE-2026-7774 CVE-2026-8328
-----------------------------------------------------------------
The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 853
Released: Tue Aug 18 13:57:55 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1258364,1261969,1262098,1262319,1262654,1263083,1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-1502,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328
This update for python311 fixes the following issues:
Security issues fixed:
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
`configparser` module is used (bsc#1269066).
- CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted
Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
hardlinks (bsc#1269959).
- CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319).
- CVE-2026-6019: BaseCookie.js_output() does not neutralize embedded characters (bsc#1262654).
- CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules
(bsc#1262098).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding
protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory
(bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
(bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
(bsc#1271192).
Non security issues fixed:
- Regression in `http.cookies` (bsc#1263083).
- udplite was removed -> python fails in tests (bsc#1268375).
- Conflicts between different versions of Python (bsc#1258364).
The following package changes have been done:
- SL-Micro-release-6.0-25.123 updated
- libpython3_11-1_0-3.11.15-5.1 updated
- python311-base-3.11.15-5.1 updated
- skelcd-EULA-SL-Micro-2024.01.19-8.122 updated
More information about the sle-container-updates
mailing list