Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: Moderate Python 3.11 Security Update 2025:21207-1 CVE-2025-6075

suse
Calendar Grey December 16, 2025
Dist Suse Esm H88
Install the new SUSE security update for python311 to fix two moderate vulnerabilities related to environment variables.
An update that solves two vulnerabilities can now be installed.

Summary

## This update for python311 fixes the following issues: Update to 3.11.14: * CVE-2025-8291: Fixed validity of the ZIP64 End of Central Directory (EOCD) is not checked by the 'zipfile' module (bsc#1251305). * CVE-2025-6075: Fixed the value passed to os.path.expandvars() is user- controlled a performance degradation is possible when expanding environment variables (bsc#1252974). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-347=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python311-base-debuginfo-3.11.14-slfo.1.1_1.1

References

* bsc#1251305

* bsc#1252974

Cross-

* CVE-2025-6075

* CVE-2025-8291

CVSS scores:

* CVE-2025-6075 ( SUSE ): 1.8

CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-6075 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-6075 ( NVD ): 1.8

CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-8291 ( SUSE ): 4.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2025-8291 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Announcement ID: SUSE-SU-2025:21207-1
Release Date: 2025-12-09T17:00:05Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here