An update that solves one vulnerability can now be installed.. # Security update for python-idna Announcement ID: SUSE-SU-2026:21914-1 Release Date: 2026-05-28T15:43:54Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-733=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * python311-idna-3.4-9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 . SUSE Linux Micro updates resolve a moderate security issue in python-idna. Important for maintaining system integrity.. SUSE Linux Micro security update, python-idna bug fix, security advisory moderate, input encoding issue, system security patch. . Severity: moderate. LinuxSecurity.com Team
Fix for CVE-2023-24329. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-994ecd7dbc 2023-05-31 17:29:34.390126 --------------------------------------------------------------------------------Name : python3.10 Product : Fedora 38 Version : 3.10.11 Release : 2.fc38 URL : https://www.python.org/ Summary : Version 3.10 of the Python interpreter Description : Python 3.10 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.10 package provides the "python3.10" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.10-libs package, which should be installed automatically along with python3.10. The remaining parts of the Python standard library are broken out into the python3.10-tkinter and python3.10-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.10-docs package. Packages containing additional libraries for Python are generally named with the "python3.10-" prefix. --------------------------------------------------------------------------------Update Information: Fix for CVE-2023-24329 --------------------------------------------------------------------------------ChangeLog: * Mon May 29 2023 Charalampos Stratakis - 3.10.11-2 - Fix for CVE-2023-24329 Resolves: rhbz#2174010 --------------------------------------------------------------------------------References: [ 1 ] Bug #2174010 - CVE-2023-24329 python3.10: python: urllib.parse url blocklisting bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2174010 --------------------------------------------------------------------------------This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-994ecd7dbc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for nodejs14 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3614-1 Rating: moderate References: #1201325 #1203832 Cross-References: CVE-2022-32213 CVE-2022-35256 CVSS scores: CVE-2022-32213 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2022-32213 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H CVE-2022-35256 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Web Scripting 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for nodejs14 fixes the following issues: Updated to version 14.20.1: - CVE-2022-32213: Fixed bypass via obs-fold mechanic (bsc#1201325). - CVE-2022-35256: Fixed incorrect Parsing of Header Fields (bsc#1203832). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3614=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3614=1 - SUSE Linux Enterprise Modulefor Web Scripting 15-SP3: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP3-2022-3614=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): corepack14-14.20.1-150200.15.37.1 nodejs14-14.20.1-150200.15.37.1 nodejs14-debuginfo-14.20.1-150200.15.37.1 nodejs14-debugsource-14.20.1-150200.15.37.1 nodejs14-devel-14.20.1-150200.15.37.1 npm14-14.20.1-150200.15.37.1 - openSUSE Leap 15.4 (noarch): nodejs14-docs-14.20.1-150200.15.37.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): nodejs14-14.20.1-150200.15.37.1 nodejs14-debuginfo-14.20.1-150200.15.37.1 nodejs14-debugsource-14.20.1-150200.15.37.1 nodejs14-devel-14.20.1-150200.15.37.1 npm14-14.20.1-150200.15.37.1 - openSUSE Leap 15.3 (noarch): nodejs14-docs-14.20.1-150200.15.37.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP3 (aarch64 ppc64le s390x x86_64): nodejs14-14.20.1-150200.15.37.1 nodejs14-debuginfo-14.20.1-150200.15.37.1 nodejs14-debugsource-14.20.1-150200.15.37.1 nodejs14-devel-14.20.1-150200.15.37.1 npm14-14.20.1-150200.15.37.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP3 (noarch): nodejs14-docs-14.20.1-150200.15.37.1 References: https://www.suse.com/security/cve/CVE-2022-32213.html https://www.suse.com/security/cve/CVE-2022-35256.html https://bugzilla.suse.com/1201325 https://bugzilla.suse.com/1203832 . SUSE Security Update for nodejs14: Fixes moderate issues in latest patch. Update your systems for enhanced security.. SUSE Linux, NodeJS, Security Update, Patch Management, Software Vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.