SUSE-SU-2026:23743-1: important: Security update for python311

SLE-SECURITY-UPDATES null at suse.de
Mon Sep 21 09:17:34 UTC 2026


# Security update for python311

Announcement ID: SUSE-SU-2026:23743-1  
Release Date: 2026-09-16T09:53:12Z  
Rating: important  
References:

  * bsc#1259240
  * bsc#1259611
  * bsc#1259734
  * bsc#1259735
  * bsc#1260026
  * bsc#1261969
  * bsc#1262098
  * bsc#1262319
  * bsc#1264962
  * bsc#1265268
  * bsc#1267581
  * bsc#1267821
  * bsc#1267974
  * bsc#1268977
  * bsc#1269066
  * bsc#1269788
  * bsc#1269959
  * bsc#1271192
  * bsc#1276223
  * bsc#1276226

  
Cross-References:

  * CVE-2021-4189
  * CVE-2025-13462
  * CVE-2025-4330
  * CVE-2026-0864
  * CVE-2026-11940
  * CVE-2026-11972
  * CVE-2026-1502
  * CVE-2026-15308
  * CVE-2026-15806
  * CVE-2026-17084
  * CVE-2026-2297
  * CVE-2026-3276
  * CVE-2026-3644
  * CVE-2026-4224
  * CVE-2026-4360
  * CVE-2026-45186
  * CVE-2026-4519
  * CVE-2026-4786
  * CVE-2026-6100
  * CVE-2026-7210
  * CVE-2026-72522
  * CVE-2026-7774
  * CVE-2026-8328
  * CVE-2026-9669

  
CVSS scores:

  * CVE-2021-4189 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2021-4189 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2021-4189 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2025-13462 ( SUSE ):  2.0
    CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2025-13462 ( SUSE ):  2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
  * CVE-2025-13462 ( NVD ):  2.0
    CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2025-13462 ( NVD ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  * CVE-2025-4330 ( SUSE ):  8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  * CVE-2025-4330 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-0864 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-0864 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-0864 ( NVD ):  4.1
    CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-0864 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11940 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-11940 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11940 ( NVD ):  7.8
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-11972 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-11972 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11972 ( NVD ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-1502 ( SUSE ):  5.7
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-1502 ( SUSE ):  4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-1502 ( NVD ):  5.7
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-15308 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-15308 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-15308 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-15308 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-15806 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-15806 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-15806 ( NVD ):  6.0
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-17084 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-17084 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-17084 ( NVD ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-2297 ( SUSE ):  5.7
    CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-2297 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-2297 ( NVD ):  5.7
    CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-3276 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-3276 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-3276 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-3644 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-3644 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-3644 ( NVD ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-3644 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-4224 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-4224 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-4224 ( NVD ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4224 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-4360 ( SUSE ):  2.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-4360 ( SUSE ):  2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-4360 ( NVD ):  2.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4360 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-45186 ( SUSE ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-45186 ( NVD ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-45186 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-45186 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-4519 ( SUSE ):  7.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N
  * CVE-2026-4519 ( SUSE ):  6.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N
  * CVE-2026-4519 ( NVD ):  7.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4519 ( NVD ):  7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
  * CVE-2026-4519 ( NVD ):  3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-4786 ( SUSE ):  7.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4786 ( SUSE ):  7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
  * CVE-2026-4786 ( NVD ):  7.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4786 ( NVD ):  7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
  * CVE-2026-6100 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-6100 ( SUSE ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-6100 ( NVD ):  9.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-6100 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-7210 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-7210 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-7210 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-7210 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-72522 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-72522 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-72522 ( NVD ):  6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-7774 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-7774 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-7774 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-8328 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-8328 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-8328 ( NVD ):  5.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-9669 ( SUSE ):  5.7
    CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-9669 ( SUSE ):  4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-9669 ( NVD ):  8.2
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

  
Affected Products:

  * SUSE Linux Micro 6.1

  
  
An update that solves 24 vulnerabilities can now be installed.

## Description:

This update for python311 fixes the following issues:

  * CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and
    type AREGTYPE are combined (bsc#1259611).
  * CVE-2026-0864: improper handling of line-ending characters can lead to
    configuration file injection when the `configparser` module is used
    (bsc#1269066).
  * CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF
    (bsc#1261969).
  * CVE-2026-2297: cpython: incorrectly handled hook in FileLoader can lead to
    validation bypass (bsc#1259240).
  * CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to
    DoS when processing specially crafted Unicode input (bsc#1267581).
  * CVE-2026-3644: incomplete control character validation in http.cookies
    (bsc#1259734).
  * CVE-2026-4224: C stack overflow when parsing XML with deeply nested DTD
    content models (bsc#1259735).
  * CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is
    not passed properly when extracting hardlinks (bsc#1269959).
  * CVE-2026-4519: leading dashes in URLs are accepted by the
    `webbrowser.open()` API and allow for web browser command line option
    injection (bsc#1260026).
  * CVE-2026-4786: Incomplete mitigation of %action expansion for command
    injection to webbrowser.open() (bsc#1262319).
  * CVE-2026-6100: Arbitrary code execution or information disclosure via use-
    after-free in decompression modules (bsc#1262098).
  * CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use
    insufficient entropy for Expat hash-flooding protection (bsc#1264962).
  * CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing
    outside the extraction directory (bsc#1267821).
  * CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-
    supplied PASV host address (bsc#1265268).
  * CVE-2026-9669: crafted input can cause a stack buffer overflow
    (bsc#1267974).
  * CVE-2026-11940: tarfile extraction filter bypass via a crafted archive
    allows escaping the destination directory and enables arbitrary file reads
    and writes (bsc#1268977).
  * CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile
    module streaming mode can lead to DoS (bsc#1269788).
  * CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via
    repeated unterminated markup declarations (bsc#1271192).
  * CVE-2026-15806: urllib.request.HTTPPasswordMgr credentials for one URL
    scheme sent over another scheme (bsc#1276223).
  * CVE-2026-17084: StringPrep algorithm considered Unicode codepoint attributes
    outside Unicode 3.2.0 (bsc#1276226).

Changes for python311:

  * Update to 3.11.16:
  * Build
  * gh-153438: Update Windows build and installer tooling and documentation to
    use the current download URL for nuget.exe.
  * Library
  * gh-109638: Fix exponential time in csv.Sniffer.sniff() for a sample which
    contains many quote characters. A doubled quote character is now also
    detected in a field which contains the delimiter or a line break.
  * gh-98820: Fix quadratic time in csv.Sniffer.sniff() for a sample which
    contains quoted fields, in particular for a single column of quoted fields.
  * gh-149231: In tomllib, the number of parts in TOML keys is now limited.
  * gh-146083: Update bundled libexpat to version 2.7.5.
  * gh-141707: Don't change tarfile.TarInfo type from AREGTYPE to DIRTYPE when
    parsing GNU long name or link headers (bsc#1259611, CVE-2025-13462).
  * gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and
    SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects
    to tune protections against billion laughs attacks. Patch by Bénédikt Tran.
  * gh-100372: ssl.SSLContext.load_verify_locations() no longer incorrectly
    accepts some cases of trailing data when parsing DER.
  * Security
  * gh-155558: Update bundled libexpat to version 2.8.3 for the fix to
    CVE-2026-72522.
  * gh-153030: Fixed quadratic complexity in incremental parsing of long
    unterminated constructs (such as tags or comments) in
    html.parser.HTMLParser, which could be exploited for a denial of service
    (bsc#1271192, CVE-2026-15308).
  * gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind()
    and find() avoid quadratic behavior when using XPath index predicates ([1],
    [last()], [last()-N]) on XML documents with many same-tag siblings.
  * gh-152216: Update bundled libexpat to version 2.8.2.
  * gh-151987: The tarfile.TarFile.extract() method now applies the given filter
    when it extracts a link target from the archive as a fallback (bsc#1269959,
    CVE-2026-4360).
  * gh-151981: In tarfile, seeking a stream now stops when end of the stream is
    reached (bsc#1269788, CVE-2026-11972).
  * gh-151544: Modules/Setup.local is no longer used as a landmark to discover
    whether Python is running in a source tree, as it could potentially affect
    actual installs. The pybuilddir.txt file is now the sole indicator of
    running in a source tree.
  * gh-151558: Fixed an vulnerability in the tarfile data and tar extraction
    filters where crafted archives could create a symlink pointing outside the
    destination directory. This was a bypass of CVE-2025-4330 (bsc#1268977,
    CVE-2026-11940).
  * gh-150599: Fix a possible stack buffer overflow in bz2 when a
    bz2.BZ2Decompressor is reused after a decompression error. The decompressor
    now becomes unusable after libbz2 reports an error (bsc#1267974,
    CVE-2026-9669).
  * gh-150743: http.client now limits the number of chunked-response trailer
    lines it will read to 100, and the number of interim (1xx) responses it will
    skip to 100. A malicious or broken server could previously stream trailer
    lines or 100 Continue responses forever, hanging the client even when a
    socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4.
  * gh-149698: Update bundled libexpat to version 2.8.1 for the fix for
    CVE-2026-45186.
  * gh-87451: The ftplib module's undocumented ftpcp function no longer trusts
    the IPv4 address value returned from the source server in response to the
    PASV command by default, completing the fix for CVE-2021-4189. As with
    ftplib.FTP, the former behavior can be re-enabled by setting the
    trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance
    to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268,
    CVE-2026-8328).
  * gh-149486: tarfile.data_filter() now validates link targets using the same
    normalised value that is written to disk, strips trailing separators from
    the member name when resolving a symlink's directory, and rejects link
    members that would replace the destination directory itself. This closes
    several path-traversal bypasses of the data extraction filter (bsc#1267821,
    CVE-2026-7774).
  * gh-149079: Fix a potential denial of service in unicodedata.normalize(). The
    canonical ordering step of Unicode normalization used a quadratic-time
    insertion sort for reordering combining characters, which could be exploited
    with crafted input containing many combining characters in non-canonical
    order. Replaced with a linear-time counting sort for long runs (bsc#1267581,
    CVE-2026-3276).
  * gh-149018: Improved protection against XML hash-flooding attacks in
    xml.parsers.expat and xml.etree.ElementTree when Python is compiled with
    libExpat 2.8.0 or later (bsc#1264962, CVE-2026-7210).
  * gh-149017: Update bundled libexpat to version 2.8.0.
  * gh-148808: Added buffer boundary check when using nbytes parameter with
    asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows
    and the asyncio.ProactorEventLoop.
  * gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, and
    bz2.BZ2Decompressor when memory allocation fails with MemoryError, which
    could let a subsequent decompress() call read or write through a stale
    pointer to the already-released caller buffer (bsc#1262098, CVE-2026-6100).
  * gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass
    the dash-prefix safety check (bsc#1262319, CVE-2026-4786).
  * gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on
    Windows which allowed to write files outside of the destination tree if the
    patch in the archive contains a Windows drive prefix. Now such invalid paths
    will be skipped. Files containing ".." in the name (like "foo..bar") are no
    longer skipped.
  * gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option
    parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with
    many whitespace characters could cause excessive CPU usage.
  * gh-146211: Reject CR/LF characters in tunnel request headers for the
    HTTPConnection.set_tunnel() method (bsc#1261969, CVE-2026-1502).
  * gh-145986: xml.parsers.expat: Fixed a crash caused by unbounded C recursion
    when converting deeply nested XML content models with ElementDeclHandler().
    This addresses CVE-2026-4224 (bsc#1259735, CVE-2026-4224).
  * gh-145599: Reject control characters in http.cookies.Morsel update() and
    js_output(). This addresses CVE-2026-3644 (bsc#1259734, CVE-2026-3644).
  * gh-145506: Fixes CVE-2026-2297 by ensuring that SourcelessFileLoader uses
    io.open_code() when opening .pyc files (bsc#1259240, CVE-2026-2297).
  * gh-144370: Disallow usage of control characters in status in
    wsgiref.handlers to prevent HTTP header injections. Patch by Benedikt
    Johannes.
  * gh-143930: Reject leading dashes in URLs passed to webbrowser.open()
    (bsc#1260026, CVE-2026-4519).
  * gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when
    writing multi-line configparser values (bsc#1269066, CVE-2026-0864).
  * Tests
  * gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite
    tests if it's not supported. Patch by Victor Stinner.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Micro 6.1  
    zypper in -t patch SUSE-SLE-Micro-6.1-733

## Package List:

  * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64)
    * python311-debuginfo-3.11.16-slfo.1.1_1.1
    * libpython3_11-1_0-debuginfo-3.11.16-slfo.1.1_1.1
    * python311-core-debugsource-3.11.16-slfo.1.1_1.1
    * python311-curses-3.11.16-slfo.1.1_1.1
    * python311-base-3.11.16-slfo.1.1_1.1
    * python311-base-debuginfo-3.11.16-slfo.1.1_1.1
    * libpython3_11-1_0-3.11.16-slfo.1.1_1.1
    * python311-curses-debuginfo-3.11.16-slfo.1.1_1.1
    * python311-debugsource-3.11.16-slfo.1.1_1.1
    * python311-3.11.16-slfo.1.1_1.1

## References:

  * https://www.suse.com/security/cve/CVE-2021-4189.html
  * https://www.suse.com/security/cve/CVE-2025-13462.html
  * https://www.suse.com/security/cve/CVE-2025-4330.html
  * https://www.suse.com/security/cve/CVE-2026-0864.html
  * https://www.suse.com/security/cve/CVE-2026-11940.html
  * https://www.suse.com/security/cve/CVE-2026-11972.html
  * https://www.suse.com/security/cve/CVE-2026-1502.html
  * https://www.suse.com/security/cve/CVE-2026-15308.html
  * https://www.suse.com/security/cve/CVE-2026-15806.html
  * https://www.suse.com/security/cve/CVE-2026-17084.html
  * https://www.suse.com/security/cve/CVE-2026-2297.html
  * https://www.suse.com/security/cve/CVE-2026-3276.html
  * https://www.suse.com/security/cve/CVE-2026-3644.html
  * https://www.suse.com/security/cve/CVE-2026-4224.html
  * https://www.suse.com/security/cve/CVE-2026-4360.html
  * https://www.suse.com/security/cve/CVE-2026-45186.html
  * https://www.suse.com/security/cve/CVE-2026-4519.html
  * https://www.suse.com/security/cve/CVE-2026-4786.html
  * https://www.suse.com/security/cve/CVE-2026-6100.html
  * https://www.suse.com/security/cve/CVE-2026-7210.html
  * https://www.suse.com/security/cve/CVE-2026-72522.html
  * https://www.suse.com/security/cve/CVE-2026-7774.html
  * https://www.suse.com/security/cve/CVE-2026-8328.html
  * https://www.suse.com/security/cve/CVE-2026-9669.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1259240
  * https://bugzilla.suse.com/show_bug.cgi?id=1259611
  * https://bugzilla.suse.com/show_bug.cgi?id=1259734
  * https://bugzilla.suse.com/show_bug.cgi?id=1259735
  * https://bugzilla.suse.com/show_bug.cgi?id=1260026
  * https://bugzilla.suse.com/show_bug.cgi?id=1261969
  * https://bugzilla.suse.com/show_bug.cgi?id=1262098
  * https://bugzilla.suse.com/show_bug.cgi?id=1262319
  * https://bugzilla.suse.com/show_bug.cgi?id=1264962
  * https://bugzilla.suse.com/show_bug.cgi?id=1265268
  * https://bugzilla.suse.com/show_bug.cgi?id=1267581
  * https://bugzilla.suse.com/show_bug.cgi?id=1267821
  * https://bugzilla.suse.com/show_bug.cgi?id=1267974
  * https://bugzilla.suse.com/show_bug.cgi?id=1268977
  * https://bugzilla.suse.com/show_bug.cgi?id=1269066
  * https://bugzilla.suse.com/show_bug.cgi?id=1269788
  * https://bugzilla.suse.com/show_bug.cgi?id=1269959
  * https://bugzilla.suse.com/show_bug.cgi?id=1271192
  * https://bugzilla.suse.com/show_bug.cgi?id=1276223
  * https://bugzilla.suse.com/show_bug.cgi?id=1276226

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260921/a4828802/attachment.htm>


More information about the sle-security-updates mailing list