gpp_maybe
Security update for python311
SUSE-SLE-Module-Basesystem-15-SP7-2026-3560
This update for python311 fixes the following issues: Security issues fixed: - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issue fixed: - [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).
-
Release DateAug 10 2026
-
ReferencesBugzilla: 1264962, 1265268, 1267581, 1267821, 1268375, 1268977, 1269066, 1269788, 1269959, 1271192
CVEs: CVE-2026-0864, CVE-2026-3276, CVE-2026-4360, CVE-2026-7210, CVE-2026-7774, CVE-2026-8328, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.7 s390x
-
Packageslibpython3_11-1_0
Python Interpreter shared librarypython311-base3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter and Stdlib Corepython311-core3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter3.11.15-150600.3.62.2 lock src
Basesystem Module 15.7 aarch64
-
Packageslibpython3_11-1_0
Python Interpreter shared librarypython311-base3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter and Stdlib Corepython311-core3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter3.11.15-150600.3.62.2 lock src
Basesystem Module 15.7 ppc64le
-
Packageslibpython3_11-1_0
Python Interpreter shared librarypython311-base3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter and Stdlib Corepython311-core3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter3.11.15-150600.3.62.2 lock src
Basesystem Module 15.7 x86_64
-
Packageslibpython3_11-1_0
Python Interpreter shared librarypython311-base3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter and Stdlib Corepython311-core3.11.15-150600.3.62.2 lock rpm
Python 3 Interpreter3.11.15-150600.3.62.2 lock src