Alerts This Week
Warning Icon 1 1,220
Alerts This Week
Warning Icon 1 1,220

SUSE Python311 Important Denial Service Issues SUSE-2026-1117-1

suse
Calendar Grey March 27, 2026
Dist Suse Esm H88
An important update for python311 addressing 10 issues including memory and header injection vulnerabilities.
An update that solves 10 vulnerabilities can now be installed.

Summary

## This update for python311 fixes the following issues: Update to python 3.11.15: * CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). * CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). * CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). * CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). * CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). * CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). * CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). * CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields,

References

* bsc#1252974

* bsc#1254400

* bsc#1254401

* bsc#1254997

* bsc#1257029

* bsc#1257031

* bsc#1257042

* bsc#1257046

* bsc#1257181

* bsc#1259240

Cross-

* CVE-2025-11468

* CVE-2025-12084

* CVE-2025-13836

* CVE-2025-13837

* CVE-2025-15282

* CVE-2025-6075

* CVE-2026-0672

* CVE-2026-0865

* CVE-2026-1299

* CVE-2026-2297

CVSS scores:

* CVE-2025-11468 ( SUSE ): 7.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2025-11468 ( NVD ): 5.7

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-12084 ( SUSE ): 6.3

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1117-1
Release Date: 2026-03-27T11:34:37Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here