Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE: python39 Moderate Update for Availability DoS Issues 2025:4522-1

opensuse
Calendar Grey December 26, 2025
Dist Opensuse Esm H88
This update for python39 addresses three vulnerabilities leading to potential availability and DoS issues.
An update that solves three vulnerabilities can now be installed.

Description

This update for python39 fixes the following issues:

* CVE-2025-12084: quadratic complexity when building nested elements using

`xml.dom.minidom` methods that depend on `_clear_id_cache()` can lead to

availability issues when building excessively nested documents

(bsc#1254997).

* CVE-2025-13836: use of `Content-Length` by default when reading an HTTP

response with no read amount specified can lead to OOM issues and DoS when a

client deals with a malicious server (bsc#1254400).

* CVE-2025-13837: data read by the plistlib module according to the size

specified by the file itself can lead to OOM issues and DoS (bsc#1254401).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.3

zypper in -t patch SUSE-2025-4522=1

* openSUSE Leap 15.6

zypper in -t patch openSUSE-SLE-15.6-2025-4522=1

Package List

* openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586)

* python39-devel-3.9.25-150300.4.90.1

* python39-debuginfo-3.9.25-150300.4.90.1

* libpython3_9-1_0-3.9.25-150300.4.90.1

* python39-tools-3.9.25-150300.4.90.1

* python39-doc-devhelp-3.9.25-150300.4.90.1

* python39-dbm-debuginfo-3.9.25-150300.4.90.1

* python39-base-3.9.25-150300.4.90.1

* python39-curses-debuginfo-3.9.25-150300.4.90.1

* python39-idle-3.9.25-150300.4.90.1

* python39-debugsource-3.9.25-150300.4.90.1

* libpython3_9-1_0-debuginfo-3.9.25-150300.4.90.1

* python39-doc-3.9.25-150300.4.90.1

* python39-tk-3.9.25-150300.4.90.1

* python39-core-debugsource-3.9.25-150300.4.90.1

* python39-testsuite-debuginfo-3.9.25-150300.4.90.1

* python39-base-debuginfo-3.9.25-150300.4.90.1

* python39-3.9.25-150300.4.90.1

* python39-curses-3.9.25-150300.4.90.1

* python39-tk-debuginfo-3.9.25-150300.4.90.1

* python39-testsuite-3.9.25-150300.4.90.1

* python39-dbm-3.9.25-150300.4.90.1

* openSUSE Leap 15.3 (x86_64)

* libpython3_9-1_0-32bit-3.9.25-150300.4.90.1

*...

Read the Full Advisory

References

* bsc#1254400

* bsc#1254401

* bsc#1254997

## References:

* https://www.suse.com/security/cve/CVE-2025-12084.html

* https://www.suse.com/security/cve/CVE-2025-13836.html

* https://www.suse.com/security/cve/CVE-2025-13837.html

* https://bugzilla.suse.com/show_bug.cgi?id=1254400

* https://bugzilla.suse.com/show_bug.cgi?id=1254401

* https://bugzilla.suse.com/show_bug.cgi?id=1254997

Announcement ID: SUSE-SU-2025:4522-1
Release Date: 2025-12-26T10:35:06Z
Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here