openSUSE-SU-2026:0314-1: moderate: Security update for python-PyPDF2

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for python-PyPDF2
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0314-1
Rating:             moderate
References:         #1212797 #1262669 #1262675 #1262676 #1266821 
                    #1266822 
Cross-References:   CVE-2023-36464 CVE-2026-41168 CVE-2026-41312
                    CVE-2026-41314 CVE-2026-48156 CVE-2026-48735
                   
Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes 6 vulnerabilities is now available.

Description:

   This update for python-PyPDF2 fixes the following issues:

   - CVE-2026-48735: python-pypdf: Prior to 6.12.1, an attacker who uses this
     vulnerability can craft a PDF which leads to large memory usage
     (boo#1266821)
   - CVE-2026-48156: python-pypdf: Prior to 6.12.0, an attacker who uses this
     vulnerability can craft a PDF which leads to long runtimes (boo#1266822)
   - CVE-2023-36464: Possible Infinite Loop when a comment isn't followed by
     a character (boo#1212797)
   - CVE-2026-41312: python-pypdf: crafed PDF can lead to resources
     exhaustion (boo#1262675)
   - CVE-2026-41314: python-pypdf: manipulated FlateDecode image dimensions
     can lead to RAM exhaustion (boo#1262669)
   - CVE-2026-41168: python-pypdf: crafed PDF with cross-reference streams
     can lead to long runtimes (boo#1262676)


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-314=1



Package List:

   - openSUSE Backports SLE-15-SP7 (noarch):

      python3-PyPDF2-1.26.0-bp157.3.3.1


References:

   https://www.suse.com/security/cve/CVE-2023-36464.html
   https://www.suse.com/security/cve/CVE-2026-41168.html
   https://www.suse.com/security/cve/CVE-2026-41312.html
   https://www.suse.com/security/cve/CVE-2026-41314.html
   https://www.suse.com/security/cve/CVE-2026-48156.html
   https://www.suse.com/security/cve/CVE-2026-48735.html
   https://bugzilla.suse.com/1212797
   https://bugzilla.suse.com/1262669
   https://bugzilla.suse.com/1262675
   https://bugzilla.suse.com/1262676
   https://bugzilla.suse.com/1266821
   https://bugzilla.suse.com/1266822
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.