Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: python313 Moderate Security Fix CVE-2025-6069 DoS 2025:3706-1

suse
Calendar Grey October 21, 2025
Dist Suse Esm H88
Critical SUSE security update for python313 fixes weaknesses with moderate severity, ensuring system protection against threats.
* bsc#1244705 * bsc#1247249 Cross-References: * CVE-2025-6069

Summary

## This update for python313 fixes the following issues: Update to version 3.13.7. * Fixes in 3.13.7: * gh-137583: Fix a deadlock introduced in 3.13.6 when a call to ssl.SSLSocket.recv was blocked in one thread, and then another method on the object (such as ssl.SSLSocket.send) was subsequently called in another thread. * gh-137044: Return large limit values as positive integers instead of negative integers in resource.getrlimit(). Accept large values and reject negative values (except RLIM_INFINITY) for limits in resource.setrlimit(). * gh-136914: Fix retrieval of doctest.DocTest.lineno for objects decorated with functools.cache() or functools.cached_property. * gh-131788: Make ResourceTracker.send from multiprocessing re-entrant safe

References

* bsc#1244705

* bsc#1247249

Cross-

* CVE-2025-6069

* CVE-2025-8194

CVSS scores:

* CVE-2025-6069 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H

* CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

* CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-8194 ( SUSE ): 7.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-8194 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-8194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* Python 3 Module 15-SP7

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Server 15 SP7

* SUSE Linux Enterprise Server for SAP Applications 15 SP7

Announcement ID: SUSE-SU-2025:3706-1
Release Date: 2025-10-21T15:07:42Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here