SUSE-SU-2026:3649-1: important: Security update for python313

SLE-UPDATES null at suse.de
Wed Aug 19 16:30:40 UTC 2026


# Security update for python313

Announcement ID: SUSE-SU-2026:3649-1  
Release Date: 2026-08-19T09:54:54Z  
Rating: important  
References:

  * bsc#1257041
  * bsc#1257044
  * bsc#1262429
  * bsc#1263083
  * bsc#1264962
  * bsc#1265268
  * bsc#1267581
  * bsc#1267821
  * bsc#1268977
  * bsc#1269066
  * bsc#1269788
  * bsc#1269959
  * bsc#1271192

  
Cross-References:

  * CVE-2025-15366
  * CVE-2025-15367
  * CVE-2026-0864
  * CVE-2026-11940
  * CVE-2026-11972
  * CVE-2026-15308
  * CVE-2026-3219
  * CVE-2026-3276
  * CVE-2026-4360
  * CVE-2026-45186
  * CVE-2026-7210
  * CVE-2026-7774
  * CVE-2026-8328

  
CVSS scores:

  * CVE-2025-15366 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2025-15366 ( SUSE ):  6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
  * CVE-2025-15366 ( NVD ):  5.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2025-15367 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2025-15367 ( SUSE ):  6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
  * CVE-2025-15367 ( NVD ):  5.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-0864 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-0864 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-0864 ( NVD ):  4.1
    CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-0864 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11940 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-11940 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11940 ( NVD ):  7.8
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-11972 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-11972 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11972 ( NVD ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-15308 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-15308 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-15308 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-15308 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-3219 ( SUSE ):  4.6
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-3219 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-3219 ( NVD ):  4.6
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-3276 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-3276 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-3276 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4360 ( SUSE ):  2.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-4360 ( SUSE ):  2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-4360 ( NVD ):  2.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4360 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-45186 ( SUSE ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-45186 ( NVD ):  2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-45186 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-45186 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-7210 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-7210 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-7210 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-7210 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-7774 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-7774 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-7774 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-8328 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-8328 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-8328 ( NVD ):  5.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

  
Affected Products:

  * Python 3 Module 15-SP7
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves 13 vulnerabilities can now be installed.

## Description:

This update for python313 fixes the following issues:

  * CVE-2025-15366: user-controlled command can allow additional commands
    injected using newlines (bsc#1257044).
  * CVE-2025-15367: control characters may allow the injection of additional
    commands (bsc#1257041).
  * CVE-2026-0864: improper handling of line-ending characters can lead to
    configuration file injection when the `configparser` module is used
    (bsc#1269066).
  * CVE-2026-3219: python-pip: pip doesn't reject concatenated ZIP
    (bsc#1262429).
  * CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to
    DoS when processing specially crafted Unicode input (bsc#1267581).
  * CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is
    not passed properly when extracting hardlinks (bsc#1269959).
  * CVE-2026-6100: Arbitrary code execution or information disclosure via use-
    after-free in decompression modules (bsc#1262098).
  * CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use
    insufficient entropy for Expat hash-flooding protection (bsc#1264962).
  * CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing
    outside the extraction directory (bsc#1267821).
  * CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-
    supplied PASV host address (bsc#1265268).
  * CVE-2026-11940: tarfile extraction filter bypass via a crafted archive
    allows escaping the destination directory and enables arbitrary file reads
    and writes (bsc#1268977).
  * CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile
    module streaming mode can lead to DoS (bsc#1269788).
  * CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via
    repeated unterminated markup declarations (bsc#1271192).
  * Regression in `http.cookies` (bsc#1263083).

Changes for python313:

  * Update to 3.13.14:
  * Security
  * gh-151159: Bumps the OpenSSL version to 3.0.21 on Android.
  * gh-150599: Fix a possible stack buffer overflow in bz2 when a
    bz2.BZ2Decompressor is reused after a decompression error. The decompressor
    now becomes unusable after libbz2 reports an error.
  * gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when
    checking whether the destination is inside the source directory, preventing
    a symlink-based bypass of that guard.
  * gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE
    2026-45186.
  * gh-87451: The ftplib module's undocumented ftpcp function no longer trusts
    the IPv4 address value returned from the source server in response to the
    PASV command by default, completing the fix for CVE-2021-4189. As with
    ftplib.FTP, the former behavior can be re-enabled by setting the
    trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance
    to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268,
    CVE-2026-8328)
  * gh-149486: tarfile.data_filter() now validates link targets using the same
    normalised value that is written to disk, strips trailing separators from
    the member name when resolving a symlink's directory, and rejects link
    members that would replace the destination directory itself. This closes
    several path-traversal bypasses of the data extraction filter (bsc#1267821,
    CVE-2026-7774).
  * gh-149079: Fix a potential denial of service in unicodedata.normalize(). The
    canonical ordering step of Unicode normalization used a quadratic-time
    insertion sort for reordering combining characters, which could be exploited
    with crafted input containing many combining characters in non-canonical
    order. Replaced with a linear-time counting sort for long runs (bsc#1267581,
    CVE-2026-3276).
  * gh-149018: Improved protection against XML hash-flooding attacks in
    xml.parsers.expat and xml.etree.ElementTree when Python is compiled with
    libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962).
  * gh-149017: Update bundled libexpat to version 2.8.0.
  * gh-90309: Base64-encode values when embedding cookies to JavaScript using
    the http.cookies.BaseCookie.js_output() method to avoid injection and
    escaping. (bsc#1262654, CVE-2026-6019)
  * gh-148808: Added buffer boundary check when using nbytes parameter with
    asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows
    and the asyncio.ProactorEventLoop.
  * gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor,
    bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory
    allocation fails with MemoryError, which could let a subsequent decompress()
    call read or write through a stale pointer to the already-released caller
    buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely
    applied gh#python/cpython#151605)
  * gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass
    the dash-prefix safety check (bsc#1262098, CVE-2026-6100).
  * gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on
    Windows which allowed to write files outside of the destination tree if the
    patch in the archive contains a Windows drive prefix. Now such invalid paths
    will be skipped. Files containing ".." in the name (like "foo..bar") are no
    longer skipped.
  * gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option
    parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with
    many whitespace characters could cause excessive CPU usage.
  * gh-146211: Reject CR/LF characters in tunnel request headers for the
    HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502)
  * gh-149144: Fixes an issue introduced by CVE-2026-6019 patch. atob() in
    JavaScript processes bytes as 'latin-1', switches the encoding algorithm
    from base64 to percent encoding and uses the decodeURIComponent() JavaScript
    API (bsc#1263083).
  * Core and Builtins
  * gh-151112: Fix a crash in the compiler that could occur when running out of
    memory.
  * gh-151126: Fix a crash, when there's no memory left on a device, which
    happened in:
  * code compilation - _winapi.CreateProcess()
  * Now these places raise proper MemoryError errors.
  * gh-150633: Fix the frozen importer accepting module names with embedded null
    bytes, which caused it to bypass the sys.modules cache and create duplicate
    module objects.
  * gh-149156: Fix an intermittent crash after os.fork() when perf trampoline
    profiling is enabled and the child returns through trampoline frames
    inherited from the parent process.
  * gh-149449: Fix a use-after-free crash when the unicodedata module was
    removed from sys.modules and garbage-collected between calls that decode
    \N{...} escapes or use the namereplace codec error handler.
  * gh-148450: Fix abc.register() so it invalidates type version tags for
    registered classes.
  * gh-150207: Fix a crash when a memory allocation fails during tokenizer
    initialization. A proper MemoryError is now raised instead.
  * gh-150107: asyncio: sendfile() and sock_sendfile() event loop methods now
    call file.seek(offset) if file has a seek() method, even if offset is 0
    (default value).
  * gh-150146: Fix a crash on a complex type variable substitution.
  * from typing import TypeVar; memoryview[TypeVar("")][*typing.Mapping[...,
    ...]] used to fail due to missing NULL check on _unpack_args C function
    call.
  * gh-149590: Fix crash when faulthandler is imported more than once.
  * gh-149738: sqlite3: Disallow removing row_factory and text_factory
    attributes of a connection to prevent a crash on a query.
  * gh-139808: Add branch protections for AArch64 (BTI/PAC) in assembly code
    used by -X perf_jit (Linux perf profiler integration).
  * gh-148820: Fix a race in _PyRawMutex on the free-threaded build where a
    Py_PARK_INTR return from _PySemaphore_Wait could let the waiter destroy its
    semaphore before the unlocking thread's _PySemaphore_Wakeup completed,
    causing a fatal ReleaseSemaphore error.
  * gh-148653: Forbid marshalling recursive code objects which cannot be
    correctly unmarshalled.
  * gh-148390: Fix an undefined behavior in memoryview when using the native
    boolean format (?) in cast(). Previously, on some common platforms, calling
    memoryview(b).cast("?").tolist() incorrectly returned [False] instead of
    [True] for any even byte b. Patch by Bénédikt Tran.
  * gh-148418: Fix a possible reference leak in a corrupted TYPE_CODE marshal
    stream.
  * gh-148222: Fix vectorcall support in types.GenericAlias when the underlying
    type does not support the vectorcall protocol. Fix possible leaks in
    types.GenericAlias and types.UnionType in case of memory error.
  * gh-145376: Fix reference leaks in various unusual error scenarios.
  * C API
  * gh-150907: Fix dynamic_annotations.h header file when built with C++ and
    Valgrind: add extern "C++" scope for the C++ template. Patch by Victor
    Stinner.
  * Build
  * gh-149351: Avoid possible broken macOS framework install names when DESTDIR
    is specified during builds.
  * gh-146475: Block Apple Clang from being used to build the JIT as it ships
    without required LLVM tools.
  * gh-148535: No longer use the gcc -fprofile-update=atomic flag on i686. The
    flag has been added to fix a random GCC internal error on PGO build
    (gh-145801) caused by corruption of profile data (.gcda files). The problem
    is that it makes the PGO build way slower (up to 47x slower) on i686. Since
    the GCC internal error was not seen on i686 so far, don't use -fprofile-
    update=atomic on i686 anymore. Patch by Victor Stinner.
  * Library
  * gh-150913: Fix sqlite3.Blob slice assignment to raise TypeError and
    IndexError for type and size mismatches respectively, even when the target
    slice is empty.
  * gh-143008: Fix race conditions when re-initializing a io.TextIOWrapper
    object.
  * gh-150685: Update bundled pip to 26.1.2
  * gh-150406: Fix a possible crash occurring during socket module
    initialization when the system is out of memory on platforms without a
    reentrant gethostbyname.
  * gh-150372: readline: Fix a potential crash during tab completion caused by
    an out-of-memory error during module initialization.
  * gh-150175: Fix race condition in unittest.mock.ThreadingMock where
    concurrent calls could lose increments to call_count and other attributes
    due to a missing lock in _increment_mock_call.
  * gh-84353: Preserve non-UTF-8 encoded filenames when appending to a
    zipfile.ZipFile. Previously, non-ASCII names stored in a legacy encoding
    (without the UTF-8 flag bit set) could be corrupted when the central
    directory was rewritten: they were decoded as cp437 and then re-stored as
    UTF-8.
  * gh-149995: Update various docstrings in typing.
  * gh-88726: The email package now uses standard MIME charset names "gb2312"
    and "big5" instead of non-standard names "eucgb2312_cn" and "big5_tw".
  * gh-149571: Fix the C implementation of
    xml.etree.ElementTree.Element.itertext(): it no longer emits text for
    comments and processing instructions.
  * gh-149921: Fix reference leaks in error paths of the _interpchannels and
    _interpqueues extension modules.
  * gh-149801: Add IANA registered names and aliases with leading zeros before
    number (like IBM00858, CP00858, IBM01140, CP01140) for corresponding codecs.
  * gh-149701: Fix bad return code from Lib/venv/bin/activate if hashing is
    disabled
  * gh-112821: In the REPL, autocompletion might run arbitrary code in the
    getter of a descriptor. If that getter raised an exception, autocompletion
    would fail to present any options for the entire object. Autocompletion now
    works as expected for these objects.
  * gh-149388: Make asyncio.windows_utils.PipeHandle closing idempotent.
  * gh-149489: Fix ElementTree serialization to HTML. The content of elements
    "xmp", "iframe", "noembed", "noframes", and "plaintext" is no longer
    escaped. The "plaintext" element no longer have the closing tag.
  * gh-149377: Update bundled pip to 26.1.1
  * gh-149231: In tomllib, the number of parts in TOML keys is now limited.
  * gh-149117: Fix runpy.run_module() and runpy.run_path() to set the name
    attribute on the ImportError they raise.
  * gh-149148: ensurepip: Upgrade bundled pip to 26.1. This version fixes the
    CVE 2026-3219 vulnerability. Patch by Victor Stinner.
  * gh-148093: Fix an out-of-bounds read of one byte in binascii.a2b_uu(). Raise
    binascii.Error, instead of reading past the buffer end.
  * gh-148914: Fix memoization of in-band PickleBuffer in the Python
    implementation of pickle. Previously, identical PickleBuffers did not
    preserve identity, and empty writable PickleBuffer memoized an empty
    bytearray object in place of b'', so the following references to b'' were
    unpickled as an empty bytearray object.
  * gh-138907: Support RFC 9309 in urllib.robotparser.
  * gh-148954: Fix XML injection vulnerability in xmlrpc.client.dumps() where
    the methodname was not being escaped before interpolation into the XML body.
  * gh-148801: xml.etree.ElementTree: Fix a crash in Element.**deepcopy** on
    deeply nested trees.
  * gh-148735: xml.etree.ElementTree: Fix a use-after-free in Element.findtext
    when the element tree is mutated concurrently during the search.
  * gh-146553: Fix infinite loop in typing.get_type_hints() when **wrapped**
    forms a cycle. Patch by Shamil Abdulaev.
  * gh-148508: An intermittent timing error when running SSL tests on iOS has
    been resolved.
  * gh-148518: If an email containing an address header that ended in an open
    double quote was parsed with a non-compat32 policy, accessing the username
    attribute of the mailbox accessed through that header object would result in
    an IndexError. It now correctly returns an empty string as the result.
  * gh-148370: configparser: prevent quadratic behavior when a ParsingError is
    raised after a parser fails to parse multiple lines. Patch by Bénédikt Tran.
  * gh-148254: Use singular "sec" instead of "secs" in timeit verbose output for
    consistency with other time units.
  * gh-148192: email.generator.Generator._make_boundary could fail to detect a
    duplicate boundary string if linesep was not n. It now correctly detects
    boundary strings when linesep is rn as well.
  * gh-146313: Fix a deadlock in multiprocessing's resource tracker where the
    parent process could hang indefinitely in os.waitpid() during interpreter
    shutdown if a child created via os.fork() still held the resource tracker's
    pipe open.
  * gh-145831: Fix email.quoprimime.decode() leaving a stray \r when eol='\r\n'
    by stripping the full eol string instead of one character.
  * gh-145105: Fix crash in csv reader when iterating with a re-entrant iterator
    that calls next() on the same reader from within **next**.
  * gh-130750: Restore quoting of choices in argparse error messages for
    improved clarity and consistency with documentation.
  * gh-105936: Attempting to mutate non-field attributes of dataclasses with
    both frozen and slots being True now raises FrozenInstanceError instead of
    TypeError. Their non-dataclass subclasses can now freely mutate non-field
    attributes, and the original non-slotted class can be garbage collected. The
    fix also handles the case of an empty **class** cell on a function found
    within the class (gh-148947).
  * gh-142516: ssl: fix reference leaks in ssl.SSLContext objects. Patch by
    Bénédikt Tran.
  * gh-142831: Fix a crash in the json module where a use-after-free could occur
    if the object being encoded is modified during serialization.
  * gh-140287: The asyncio REPL now handles exceptions when executing
    PYTHONSTARTUP scripts. Patch by Bartosz Sławecki.
  * gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and
    SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects
    to tune protections against billion laughs attacks. Patch by Bénédikt Tran.
  * gh-132631: Fix "I/O operation on closed file" when parsing JSON Lines file
    with JSON CLI.
  * gh-128110: Fix bug in the parsing of email address headers that could result
    in extraneous spaces in the decoded text when using a modern email policy.
    Space between pairs of adjacent RFC 2047 encoded-words is now ignored, per
    section 6.2 (and consistent with existing parsing of unstructured headers
    like Subject).
  * gh-107398: Fix tarfile stream mode exception when process the file with the
    gzip extra field.
  * gh-123853: Update the table of Windows language code identifiers (LCIDs)
    used by locale.getdefaultlocale() on Windows to protocol version 16.0
    (2024-04-23).
  * gh-70039: Fixed bug where smtplib.SMTP.starttls() could fail if
    smtplib.SMTP.connect() is called explicitly rather than implicitly.
  * gh-83281: email: improve handling trailing garbage in address lists to avoid
    throwing AttributeError in certain edge cases
  * gh-91099: imaplib.IMAP4.login() now raises exceptions with str instead of
    bytes. Patch by Florian Best.
  * IDLE
  * bpo-6699: Warn the user if a file will be overwritten when saving.
  * Documentation
  * gh-150319: Generic builtin and standard library types now document the
    meaning of their type parameters.
  * gh-148663: Document that calendar.IllegalMonthError is a subclass of both
    ValueError and IndexError since Python 3.12.
  * gh-146646: Document that glob.glob(), glob.iglob(), pathlib.Path.glob(), and
    pathlib.Path.rglob() silently suppress OSError exceptions raised from
    scanning the filesystem.
  * gh-109503: Fix documentation for shutil.move() on usage of os.rename() since
    nonatomic move might be used even if the files are on the same filesystem.
    Patch by Fang Li
  * Tests
  * gh-151130: Add more tests for PyWeakref_* C API.
  * gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite
    tests if it's not supported. Patch by Victor Stinner.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * Python 3 Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3649=1

## Package List:

  * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * python313-idle-3.13.14-150700.4.53.1
    * python313-dbm-3.13.14-150700.4.53.1
    * python313-debuginfo-3.13.14-150700.4.53.1
    * python313-base-3.13.14-150700.4.53.1
    * python313-3.13.14-150700.4.53.1
    * python313-devel-3.13.14-150700.4.53.1
    * python313-debugsource-3.13.14-150700.4.53.1
    * python313-tools-3.13.14-150700.4.53.1
    * python313-dbm-debuginfo-3.13.14-150700.4.53.1
    * libpython3_13-1_0-3.13.14-150700.4.53.1
    * python313-tk-debuginfo-3.13.14-150700.4.53.1
    * python313-tk-3.13.14-150700.4.53.1
    * python313-base-debuginfo-3.13.14-150700.4.53.1
    * libpython3_13-1_0-debuginfo-3.13.14-150700.4.53.1
    * python313-curses-3.13.14-150700.4.53.1
    * python313-core-debugsource-3.13.14-150700.4.53.1
    * python313-curses-debuginfo-3.13.14-150700.4.53.1

## References:

  * https://www.suse.com/security/cve/CVE-2025-15366.html
  * https://www.suse.com/security/cve/CVE-2025-15367.html
  * https://www.suse.com/security/cve/CVE-2026-0864.html
  * https://www.suse.com/security/cve/CVE-2026-11940.html
  * https://www.suse.com/security/cve/CVE-2026-11972.html
  * https://www.suse.com/security/cve/CVE-2026-15308.html
  * https://www.suse.com/security/cve/CVE-2026-3219.html
  * https://www.suse.com/security/cve/CVE-2026-3276.html
  * https://www.suse.com/security/cve/CVE-2026-4360.html
  * https://www.suse.com/security/cve/CVE-2026-45186.html
  * https://www.suse.com/security/cve/CVE-2026-7210.html
  * https://www.suse.com/security/cve/CVE-2026-7774.html
  * https://www.suse.com/security/cve/CVE-2026-8328.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1257041
  * https://bugzilla.suse.com/show_bug.cgi?id=1257044
  * https://bugzilla.suse.com/show_bug.cgi?id=1262429
  * https://bugzilla.suse.com/show_bug.cgi?id=1263083
  * https://bugzilla.suse.com/show_bug.cgi?id=1264962
  * https://bugzilla.suse.com/show_bug.cgi?id=1265268
  * https://bugzilla.suse.com/show_bug.cgi?id=1267581
  * https://bugzilla.suse.com/show_bug.cgi?id=1267821
  * https://bugzilla.suse.com/show_bug.cgi?id=1268977
  * https://bugzilla.suse.com/show_bug.cgi?id=1269066
  * https://bugzilla.suse.com/show_bug.cgi?id=1269788
  * https://bugzilla.suse.com/show_bug.cgi?id=1269959
  * https://bugzilla.suse.com/show_bug.cgi?id=1271192

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260819/12a9ee44/attachment.htm>


More information about the sle-updates mailing list