openSUSE-SU-2026:0314-1: moderate: Security update for python-PyPDF2
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE Security Update: Security update for python-PyPDF2
______________________________________________________________________________
Announcement ID: openSUSE-SU-2026:0314-1
Rating: moderate
References: #1212797 #1262669 #1262675 #1262676 #1266821
#1266822
Cross-References: CVE-2023-36464 CVE-2026-41168 CVE-2026-41312
CVE-2026-41314 CVE-2026-48156 CVE-2026-48735
Affected Products:
openSUSE Backports SLE-15-SP7
______________________________________________________________________________
An update that fixes 6 vulnerabilities is now available.
Description:
This update for python-PyPDF2 fixes the following issues:
- CVE-2026-48735: python-pypdf: Prior to 6.12.1, an attacker who uses this
vulnerability can craft a PDF which leads to large memory usage
(boo#1266821)
- CVE-2026-48156: python-pypdf: Prior to 6.12.0, an attacker who uses this
vulnerability can craft a PDF which leads to long runtimes (boo#1266822)
- CVE-2023-36464: Possible Infinite Loop when a comment isn't followed by
a character (boo#1212797)
- CVE-2026-41312: python-pypdf: crafed PDF can lead to resources
exhaustion (boo#1262675)
- CVE-2026-41314: python-pypdf: manipulated FlateDecode image dimensions
can lead to RAM exhaustion (boo#1262669)
- CVE-2026-41168: python-pypdf: crafed PDF with cross-reference streams
can lead to long runtimes (boo#1262676)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-314=1
Package List:
- openSUSE Backports SLE-15-SP7 (noarch):
python3-PyPDF2-1.26.0-bp157.3.3.1
References:
https://www.suse.com/security/cve/CVE-2023-36464.html
https://www.suse.com/security/cve/CVE-2026-41168.html
https://www.suse.com/security/cve/CVE-2026-41312.html
https://www.suse.com/security/cve/CVE-2026-41314.html
https://www.suse.com/security/cve/CVE-2026-48156.html
https://www.suse.com/security/cve/CVE-2026-48735.html
https://bugzilla.suse.com/1212797
https://bugzilla.suse.com/1262669
https://bugzilla.suse.com/1262675
https://bugzilla.suse.com/1262676
https://bugzilla.suse.com/1266821
https://bugzilla.suse.com/1266822