SUSE-CU-2026:11421-1: Security update of bci/python
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Oct 3 08:42:34 UTC 2026
SUSE Container Update Advisory: bci/python
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11421-1
Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.15 , bci/python:3.13.15-88.55 , bci/python:latest
Container Release : 88.55
Severity : moderate
Type : security
References : 1258364 1267974 1273099 1273148 1274683 1276226 CVE-2026-17084
CVE-2026-18503 CVE-2026-6879 CVE-2026-9669
-----------------------------------------------------------------
The container bci/python was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4401-1
Released: Wed Sep 30 10:55:58 2026
Summary: Security update for python313
Type: security
Severity: moderate
References: 1258364,1267974,1273099,1273148,1274683,1276226,CVE-2026-17084,CVE-2026-18503,CVE-2026-6879,CVE-2026-9669
This update for python313 fixes the following issues:
Security issues fixed:
- CVE-2026-6879: quadratic behavior in `xml.etree.ElementPath` index predicates can lead to a denial of service via high
CPU usage (bsc#1273148).
- CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974).
- CVE-2026-17084: [Security-announce][] StringPrep algorithm considered (bsc#1276226).
- CVE-2026-18503: attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect
sniffing and consume significant CPU (bsc#1274683).
Non security issue fixed:
- Conflicts between different versions of Python (bsc#1258364).
- Updated to version 3.13.15
The following package changes have been done:
- libpython3_13-1_0-3.13.15-150700.4.56.1 updated
- python313-base-3.13.15-150700.4.56.1 updated
- python313-3.13.15-150700.4.56.1 updated
- python313-devel-3.13.15-150700.4.56.1 updated
More information about the sle-container-updates
mailing list