Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE Leap 15.6: python312 Moderate Availability Issues 2026:0025-1

opensuse
Calendar Grey January 5, 2026
Dist Opensuse Esm H88
An openSUSE update for python312 addresses three vulnerabilities, enhancing system security.
An update that solves three vulnerabilities can now be installed.

Description

This update for python312 fixes the following issues:

* CVE-2025-12084: quadratic complexity when building nested elements using

`xml.dom.minidom` methods that depend on `_clear_id_cache()` can lead to

availability issues when building excessively nested documents

(bsc#1254997).

* CVE-2025-13836: use of `Content-Length` by default when reading an HTTP

response with no read amount specified can lead to OOM issues and DoS when a

client deals with a malicious server (bsc#1254400).

* CVE-2025-13837: data read by the plistlib module according to the size

specified by the file itself can lead to OOM issues and DoS (bsc#1254401).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-25=1 openSUSE-SLE-15.6-2026-25=1

Package List

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)

* python312-core-debugsource-3.12.12-150600.3.40.1

* python312-devel-3.12.12-150600.3.40.1

* python312-dbm-debuginfo-3.12.12-150600.3.40.1

* libpython3_12-1_0-debuginfo-3.12.12-150600.3.40.1

* python312-tk-3.12.12-150600.3.40.1

* python312-doc-devhelp-3.12.12-150600.3.40.1

* python312-debuginfo-3.12.12-150600.3.40.1

* python312-base-debuginfo-3.12.12-150600.3.40.1

* python312-debugsource-3.12.12-150600.3.40.1

* python312-testsuite-3.12.12-150600.3.40.1

* python312-testsuite-debuginfo-3.12.12-150600.3.40.1

* python312-tk-debuginfo-3.12.12-150600.3.40.1

* python312-dbm-3.12.12-150600.3.40.1

* python312-doc-3.12.12-150600.3.40.1

* python312-curses-3.12.12-150600.3.40.1

* libpython3_12-1_0-3.12.12-150600.3.40.1

* python312-idle-3.12.12-150600.3.40.1

* python312-base-3.12.12-150600.3.40.1

* python312-3.12.12-150600.3.40.1

* python312-tools-3.12.12-150600.3.40.1

* python312-curses-debuginfo-3.12.12-150600.3.40.1

* openSUSE Leap 15.6 (x86_64)

*...

Read the Full Advisory

References

* bsc#1254400

* bsc#1254401

* bsc#1254997

## References:

* https://www.suse.com/security/cve/CVE-2025-12084.html

* https://www.suse.com/security/cve/CVE-2025-13836.html

* https://www.suse.com/security/cve/CVE-2025-13837.html

* https://bugzilla.suse.com/show_bug.cgi?id=1254400

* https://bugzilla.suse.com/show_bug.cgi?id=1254401

* https://bugzilla.suse.com/show_bug.cgi?id=1254997

Announcement ID: SUSE-SU-2026:0025-1
Release Date: 2026-01-05T12:11:33Z
Affected Products: * openSUSE Leap 15.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here