This update for python-cbor2 fixes the following issues:
- CVE-2025-64076: Fixed bug in decode_definite_long_string() that causes incorrect chunk length calculation (bsc#1253746).
Already fixed in release 5.6.3:
- CVE-2024-26134: Fixed potential crash when hashing a CBORTag (bsc#1220096).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-91=1
- openSUSE Leap 16.0:
python313-cbor2-5.6.5-160000.3.1
* bsc#1220096
* bsc#1253746
References:
* https://www.suse.com/security/cve/CVE-2024-26134.html
* https://www.suse.com/security/cve/CVE-2025-64076.html
Get the latest Linux and open source security news straight to your inbox.