gpp_maybe
Security update for python
SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3635
This update for python fixes the following issues: - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1257599). - CVE-2026-3219: python-pip: pip doesn't reject concatenated ZIP (bsc#1262467). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442 bsc#1263443). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). - Regression in `http.cookies` (bsc#1263083).
-
Release DateAug 18 2026
-
ReferencesBugzilla: 1257599, 1262467, 1263083, 1263442, 1263443, 1264962, 1265268, 1266669, 1267581, 1269066, 1269788, 1271192
CVEs: CVE-2026-0864, CVE-2026-1703, CVE-2026-3219, CVE-2026-3276, CVE-2026-6357, CVE-2026-7210, CVE-2026-8328, CVE-2026-8643, CVE-2026-11972, CVE-2026-15308 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Package Hub 15.7 s390x
-
Packageslibpython2_7-1_0
Python Interpreter shared librarypython2.7.18-150000.123.1 lock rpm
Python Interpreterpython-base2.7.18-150000.123.1 lock rpm lock src
Python Interpreter base packagepython-curses2.7.18-150000.123.1 lock rpm lock src
Python Interface to the (N)Curses Librarypython-gdbm2.7.18-150000.123.1 lock rpm
Python Interface to the GDBM Librarypython-xml2.7.18-150000.123.1 lock rpm
A Python XML Interface2.7.18-150000.123.1 lock rpm
SUSE Package Hub 15.7 aarch64
-
Packageslibpython2_7-1_0
Python Interpreter shared librarypython2.7.18-150000.123.1 lock rpm
Python Interpreterpython-base2.7.18-150000.123.1 lock rpm lock src
Python Interpreter base packagepython-curses2.7.18-150000.123.1 lock rpm lock src
Python Interface to the (N)Curses Librarypython-gdbm2.7.18-150000.123.1 lock rpm
Python Interface to the GDBM Librarypython-xml2.7.18-150000.123.1 lock rpm
A Python XML Interface2.7.18-150000.123.1 lock rpm
SUSE Package Hub 15.7 ppc64le
-
Packageslibpython2_7-1_0
Python Interpreter shared librarypython2.7.18-150000.123.1 lock rpm
Python Interpreterpython-base2.7.18-150000.123.1 lock rpm lock src
Python Interpreter base packagepython-curses2.7.18-150000.123.1 lock rpm lock src
Python Interface to the (N)Curses Librarypython-gdbm2.7.18-150000.123.1 lock rpm
Python Interface to the GDBM Librarypython-xml2.7.18-150000.123.1 lock rpm
A Python XML Interface2.7.18-150000.123.1 lock rpm
SUSE Package Hub 15.7 x86_64
-
Packageslibpython2_7-1_0
Python Interpreter shared librarypython2.7.18-150000.123.1 lock rpm
Python Interpreterpython-base2.7.18-150000.123.1 lock rpm lock src
Python Interpreter base packagepython-curses2.7.18-150000.123.1 lock rpm lock src
Python Interface to the (N)Curses Librarypython-gdbm2.7.18-150000.123.1 lock rpm
Python Interface to the GDBM Librarypython-xml2.7.18-150000.123.1 lock rpm
A Python XML Interface2.7.18-150000.123.1 lock rpm