Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE 15.6 Python312 Important Memory DoS Vuln 2026-1107-1

suse
Calendar Grey March 27, 2026
Dist Suse Esm H88
SUSE released an important python312 update addressing 10 security issues, including memory denial of service vulnerabilities.
An update that solves 10 vulnerabilities can now be installed.

Summary

## This update for python312 fixes the following issues: Update to Python 3.12.13: * CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). * CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). * CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). * CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). * CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). * CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). * CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). * CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields,

References

* bsc#1252974

* bsc#1254400

* bsc#1254401

* bsc#1254997

* bsc#1257029

* bsc#1257031

* bsc#1257042

* bsc#1257046

* bsc#1257181

* bsc#1259240

Cross-

* CVE-2025-11468

* CVE-2025-12084

* CVE-2025-13836

* CVE-2025-13837

* CVE-2025-15282

* CVE-2025-6075

* CVE-2026-0672

* CVE-2026-0865

* CVE-2026-1299

* CVE-2026-2297

CVSS scores:

* CVE-2025-11468 ( SUSE ): 7.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2025-11468 ( NVD ): 5.7

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-12084 ( SUSE ): 6.3

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1107-1
Release Date: 2026-03-27T09:04:10Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here