openSUSE-SU-2026:21595-1: important: Security update for python313

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for python313
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21595-1
Rating: important
References:

  * bsc#1257041
  * bsc#1257044
  * bsc#1265268
  * bsc#1268977
  * bsc#1269066
  * bsc#1269788
  * bsc#1269959
  * bsc#1271192



Cross-References:

  * CVE-2025-15366
  * CVE-2025-15367
  * CVE-2026-0864
  * CVE-2026-11940
  * CVE-2026-11972
  * CVE-2026-15308
  * CVE-2026-4360
  * CVE-2026-8328



CVSS scores:

  * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
  * CVE-2025-15366 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
  * CVE-2025-15367 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-4360 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.

Description:

This update for python313 fixes the following issues:

- CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044).
- CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041).
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
  `configparser` module is used (bsc#1269066).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
  hardlinks (bsc#1269959).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
  enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
  (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
  (bsc#1271192).


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1465=1

Package List:

- openSUSE Leap 16.0:

  libpython3_13-1_0-3.13.14-160000.2.1
  libpython3_13-1_0-x86-64-v3-3.13.14-160000.2.1
  libpython3_13t1_0-3.13.14-160000.2.1
  python313-3.13.14-160000.2.1
  python313-base-3.13.14-160000.2.1
  python313-base-x86-64-v3-3.13.14-160000.2.1
  python313-curses-3.13.14-160000.2.1
  python313-dbm-3.13.14-160000.2.1
  python313-devel-3.13.14-160000.2.1
  python313-doc-3.13.14-160000.2.1
  python313-doc-devhelp-3.13.14-160000.2.1
  python313-idle-3.13.14-160000.2.1
  python313-nogil-3.13.14-160000.2.1
  python313-nogil-base-3.13.14-160000.2.1
  python313-nogil-curses-3.13.14-160000.2.1
  python313-nogil-dbm-3.13.14-160000.2.1
  python313-nogil-devel-3.13.14-160000.2.1
  python313-nogil-idle-3.13.14-160000.2.1
  python313-nogil-testsuite-3.13.14-160000.2.1
  python313-nogil-tk-3.13.14-160000.2.1
  python313-nogil-tools-3.13.14-160000.2.1
  python313-testsuite-3.13.14-160000.2.1
  python313-tk-3.13.14-160000.2.1
  python313-tools-3.13.14-160000.2.1
  python313-x86-64-v3-3.13.14-160000.2.1

References:

  * https://www.suse.com/security/cve/CVE-2025-15366.html
  * https://www.suse.com/security/cve/CVE-2025-15367.html
  * https://www.suse.com/security/cve/CVE-2026-0864.html
  * https://www.suse.com/security/cve/CVE-2026-11940.html
  * https://www.suse.com/security/cve/CVE-2026-11972.html
  * https://www.suse.com/security/cve/CVE-2026-15308.html
  * https://www.suse.com/security/cve/CVE-2026-4360.html
  * https://www.suse.com/security/cve/CVE-2026-8328.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.