Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE Python310 Moderate DoS Vulnerabilities SUSE-SU-2026:0130-1

opensuse
Calendar Grey January 15, 2026
Dist Opensuse Esm H88
Resolve three vulnerabilities in python310 on openSUSE with this security advisory and patch instructions.
An update that solves three vulnerabilities can now be installed.

Description

This update for python310 fixes the following issues:

* CVE-2025-12084: quadratic complexity when building nested elements using

`xml.dom.minidom` methods that depend on `_clear_id_cache()` can lead to

availability issues when building excessively nested documents

(bsc#1254997).

* CVE-2025-13836: use of `Content-Length` by default when reading an HTTP

response with no read amount specified can lead to OOM issues and DoS when a

client deals with a malicious server (bsc#1254400).

* CVE-2025-13837: data read by the plistlib module according to the size

specified by the file itself can lead to OOM issues and DoS (bsc#1254401).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch SUSE-2026-130=1

* openSUSE Leap 15.6

zypper in -t patch openSUSE-SLE-15.6-2026-130=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)

* python310-base-debuginfo-3.10.19-150400.4.94.1

* python310-curses-3.10.19-150400.4.94.1

* python310-debugsource-3.10.19-150400.4.94.1

* python310-base-3.10.19-150400.4.94.1

* python310-testsuite-3.10.19-150400.4.94.1

* python310-tk-debuginfo-3.10.19-150400.4.94.1

* python310-doc-devhelp-3.10.19-150400.4.94.1

* python310-curses-debuginfo-3.10.19-150400.4.94.1

* python310-testsuite-debuginfo-3.10.19-150400.4.94.1

* python310-3.10.19-150400.4.94.1

* python310-doc-3.10.19-150400.4.94.1

* libpython3_10-1_0-debuginfo-3.10.19-150400.4.94.1

* python310-dbm-debuginfo-3.10.19-150400.4.94.1

* python310-tk-3.10.19-150400.4.94.1

* python310-idle-3.10.19-150400.4.94.1

* python310-devel-3.10.19-150400.4.94.1

* python310-core-debugsource-3.10.19-150400.4.94.1

* python310-dbm-3.10.19-150400.4.94.1

* python310-tools-3.10.19-150400.4.94.1

* libpython3_10-1_0-3.10.19-150400.4.94.1

* python310-debuginfo-3.10.19-150400.4.94.1

* openSUSE Leap 15.4 (x86_64)

*...

Read the Full Advisory

References

* bsc#1254400

* bsc#1254401

* bsc#1254997

## References:

* https://www.suse.com/security/cve/CVE-2025-12084.html

* https://www.suse.com/security/cve/CVE-2025-13836.html

* https://www.suse.com/security/cve/CVE-2025-13837.html

* https://bugzilla.suse.com/show_bug.cgi?id=1254400

* https://bugzilla.suse.com/show_bug.cgi?id=1254401

* https://bugzilla.suse.com/show_bug.cgi?id=1254997

Announcement ID: SUSE-SU-2026:0130-1
Release Date: 2026-01-15T13:11:13Z
Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here