Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

SUSE Critical Update for Python310 Addressing Multiple DoS Vulnerabilities

suse
Calendar Grey March 26, 2026
Dist Suse Esm H88
Update for python310 addresses nine important security issues, enhancing system integrity and stability.
An update that solves nine vulnerabilities can now be installed.

Summary

## This update for python310 fixes the following issues: Update to Python 3.10.20: * CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). * CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). * CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). * CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). * CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). * CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). * CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields, values, and parameters (bsc#1257042).

References

* bsc#1252974

* bsc#1254400

* bsc#1254401

* bsc#1254997

* bsc#1257029

* bsc#1257031

* bsc#1257042

* bsc#1257181

* bsc#1259240

Cross-

* CVE-2025-11468

* CVE-2025-12084

* CVE-2025-13836

* CVE-2025-13837

* CVE-2025-6075

* CVE-2026-0672

* CVE-2026-0865

* CVE-2026-1299

* CVE-2026-2297

CVSS scores:

* CVE-2025-11468 ( SUSE ): 7.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2025-11468 ( NVD ): 5.7

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-12084 ( SUSE ): 6.3

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1062-1
Release Date: 2026-03-26T10:36:41Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here