SUSE-CU-2026:8904-1: Security update of suse/sl-micro/6.0/toolbox

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Aug 19 07:42:56 UTC 2026


SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8904-1
Container Tags        : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.151 , suse/sl-micro/6.0/toolbox:latest
Container Release     : 9.151
Severity              : important
Type                  : security
References            : 1258364 1261969 1262098 1262319 1262654 1263083 1264962 1265268
                        1267581 1267821 1268375 1268977 1269066 1269788 1269959 1271192
                        CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-1502 CVE-2026-15308
                        CVE-2026-3276 CVE-2026-4360 CVE-2026-4786 CVE-2026-6019 CVE-2026-6100
                        CVE-2026-7210 CVE-2026-7774 CVE-2026-8328 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 853
Released:    Tue Aug 18 13:57:55 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1258364,1261969,1262098,1262319,1262654,1263083,1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-1502,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328
This update for python311 fixes the following issues:

Security issues fixed:

- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
  `configparser` module is used (bsc#1269066).
- CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted
  Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
  hardlinks (bsc#1269959).
- CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319).
- CVE-2026-6019: BaseCookie.js_output() does not neutralize embedded characters (bsc#1262654).
- CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules
  (bsc#1262098).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding
  protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory
  (bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
  enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
  (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
  (bsc#1271192).

Non security issues fixed:

- Regression in `http.cookies` (bsc#1263083).
- udplite was removed -> python fails in tests (bsc#1268375).
- Conflicts between different versions of Python (bsc#1258364).


The following package changes have been done:

- SL-Micro-release-6.0-25.123 updated
- libpython3_11-1_0-3.11.15-5.1 updated
- python311-base-3.11.15-5.1 updated
- skelcd-EULA-SL-Micro-2024.01.19-8.122 updated


More information about the sle-container-updates mailing list