openSUSE-SU-2026:0277-1: important: Security update for python-nltk

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for python-nltk
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0277-1
Rating:             important
References:         #1273252 #1273254 #1273255 
Cross-References:   CVE-2026-12061 CVE-2026-12072 CVE-2026-12074
                   
Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes three vulnerabilities is now available.

Description:

   This update for python-nltk fixes the following issues:

   - CVE-2026-12061: ReDoS in NLTK ReviewsCorpusReader FEATURES regex
     (boo#1273252)
   - CVE-2026-12072: Path Traversal in NKJPCorpusReader leads to Arbitrary
     File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
     (boo#1273254)
   - CVE-2026-12074: python-nltk: path traversal in
     FramenetCorpusReader.frame() that allows arbitrary XML file read,
     bypassing the nltk.pathsec sandbox (ENFORCE=True) (boo#1273255)


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-277=1



Package List:

   - openSUSE Backports SLE-15-SP7 (noarch):

      python3-nltk-3.7-bp157.3.18.1


References:

   https://www.suse.com/security/cve/CVE-2026-12061.html
   https://www.suse.com/security/cve/CVE-2026-12072.html
   https://www.suse.com/security/cve/CVE-2026-12074.html
   https://bugzilla.suse.com/1273252
   https://bugzilla.suse.com/1273254
   https://bugzilla.suse.com/1273255
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.