openSUSE-SU-2026:0277-1: important: Security update for python-nltk
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE Security Update: Security update for python-nltk
______________________________________________________________________________
Announcement ID: openSUSE-SU-2026:0277-1
Rating: important
References: #1273252 #1273254 #1273255
Cross-References: CVE-2026-12061 CVE-2026-12072 CVE-2026-12074
Affected Products:
openSUSE Backports SLE-15-SP7
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This update for python-nltk fixes the following issues:
- CVE-2026-12061: ReDoS in NLTK ReviewsCorpusReader FEATURES regex
(boo#1273252)
- CVE-2026-12072: Path Traversal in NKJPCorpusReader leads to Arbitrary
File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
(boo#1273254)
- CVE-2026-12074: python-nltk: path traversal in
FramenetCorpusReader.frame() that allows arbitrary XML file read,
bypassing the nltk.pathsec sandbox (ENFORCE=True) (boo#1273255)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-277=1
Package List:
- openSUSE Backports SLE-15-SP7 (noarch):
python3-nltk-3.7-bp157.3.18.1
References:
https://www.suse.com/security/cve/CVE-2026-12061.html
https://www.suse.com/security/cve/CVE-2026-12072.html
https://www.suse.com/security/cve/CVE-2026-12074.html
https://bugzilla.suse.com/1273252
https://bugzilla.suse.com/1273254
https://bugzilla.suse.com/1273255