An update that solves six vulnerabilities and has one security fix can now be installed.. # Security update for python3 Announcement ID: SUSE-SU-2026:0210-1 Release Date: 2026-01-22T09:07:45Z Rating: important References: * bsc#1203750 * bsc#1244032 * bsc#1244056 * bsc#1244059 * bsc#1244060 * bsc#1244061 * bsc#1251841 Cross-References: * CVE-2007-4559 * CVE-2024-12718 * CVE-2025-4138 * CVE-2025-4330 * CVE-2025-4435 * CVE-2025-4517 CVSS scores: * CVE-2007-4559 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2007-4559 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-12718 ( NVD ): 10.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-12718 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-4138 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2025-4138 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4330 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4435 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4435 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-4517 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 Anupdate that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for python3 fixes the following issues: Security fixes: * CVE-2025-4517: Fixed arbitrary filesystem writes outside the extraction directory during extraction with filter="data" (bsc#1244032) * CVE-2025-4330: Fixed extraction filter bypass for linking outside extraction directory (bsc#1244060) * CVE-2007-4559: Fixed python tarfile module directory traversal (bsc#1203750) * CVE-2024-12718: Fixed bypass extraction filter to modify file metadata outside extraction directory (bsc#1244056) * CVE-2025-4138: Fixed symlinking targets to not point outside the destination directory, and the modification of some file metadata (bsc#1244059) * CVE-2025-4435: Fixed tarfile extracting filtered members when errorlevel=0 (bsc#1244061) Other fixes: * Fixed two shebangs with /usr/local/bin/python ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-210=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-210=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python3-devel-3.4.10-25.169.1 * python3-base-debugsource-3.4.10-25.169.1 * python3-curses-debuginfo-3.4.10-25.169.1 * python3-base-debuginfo-3.4.10-25.169.1 * libpython3_4m1_0-3.4.10-25.169.1 * libpython3_4m1_0-debuginfo-3.4.10-25.169.1 * python3-3.4.10-25.169.1 * python3-curses-3.4.10-25.169.1 * python3-debuginfo-3.4.10-25.169.1 * python3-debugsource-3.4.10-25.169.1 * python3-tk-3.4.10-25.169.1 * python3-tk-debuginfo-3.4.10-25.169.1 * python3-base-3.4.10-25.169.1 * SUSE LinuxEnterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.169.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libpython3_4m1_0-32bit-3.4.10-25.169.1 * python3-base-debuginfo-32bit-3.4.10-25.169.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.169.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python3-devel-3.4.10-25.169.1 * python3-devel-debuginfo-3.4.10-25.169.1 * python3-base-debugsource-3.4.10-25.169.1 * python3-base-debuginfo-32bit-3.4.10-25.169.1 * python3-curses-debuginfo-3.4.10-25.169.1 * python3-base-debuginfo-3.4.10-25.169.1 * libpython3_4m1_0-32bit-3.4.10-25.169.1 * libpython3_4m1_0-3.4.10-25.169.1 * libpython3_4m1_0-debuginfo-3.4.10-25.169.1 * python3-3.4.10-25.169.1 * python3-curses-3.4.10-25.169.1 * python3-debuginfo-3.4.10-25.169.1 * python3-debugsource-3.4.10-25.169.1 * python3-tk-3.4.10-25.169.1 * python3-tk-debuginfo-3.4.10-25.169.1 * python3-base-3.4.10-25.169.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.169.1 ## References: * https://www.suse.com/security/cve/CVE-2007-4559.html * https://www.suse.com/security/cve/CVE-2024-12718.html * https://www.suse.com/security/cve/CVE-2025-4138.html * https://www.suse.com/security/cve/CVE-2025-4330.html * https://www.suse.com/security/cve/CVE-2025-4435.html * https://www.suse.com/security/cve/CVE-2025-4517.html * https://bugzilla.suse.com/show_bug.cgi?id=1203750 * https://bugzilla.suse.com/show_bug.cgi?id=1244032 * https://bugzilla.suse.com/show_bug.cgi?id=1244056 * https://bugzilla.suse.com/show_bug.cgi?id=1244059 * https://bugzilla.suse.com/show_bug.cgi?id=1244060 * https://bugzilla.suse.com/show_bug.cgi?id=1244061 * https://bugzilla.suse.com/show_bug.cgi?id=1251841 . Important security update for Python3 on SUSE addressing six issues and improving system safety.. Python3 security fix, SUSE security advisory, important patch, system vulnerabilities. . Severity:Important. LinuxSecurity.com Team
* bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059 . # Security update for python3 Announcement ID: SUSE-SU-2025:02778-1 Release Date: 2025-08-13T06:47:26Z Rating: important References: * bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059 * bsc#1244060 * bsc#1244061 * bsc#1244401 * bsc#1244705 * bsc#1247249 * bsc#831629 Cross-References: * CVE-2024-12718 * CVE-2025-4138 * CVE-2025-4330 * CVE-2025-4435 * CVE-2025-4516 * CVE-2025-4517 * CVE-2025-6069 * CVE-2025-8194 CVSS scores: * CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-12718 ( NVD ): 10.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-12718 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-4138 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2025-4138 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4330 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4435 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4435 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4516 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-4516 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4516 ( NVD ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-4517 ( SUSE ): 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-4517 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-8194 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-8194 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * Development Tools Module 15-SP6 * Development Tools Module 15-SP7 * openSUSE Leap 15.3 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSELinux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves eight vulnerabilities and has three security fixes can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2025-4516: use-after-free in the unicode-escape decoder when using the error handler (bsc#1243273). * CVE-2024-12718: Fixed extraction filter bypass that allowed file metadata modification outside extraction directory (bsc#1244056) * CVE-2025-4138: Fixed issue that might allow symlink targets to point outside the destination directory, and the modification of some file metadata (bsc#1244059) * CVE-2025-4330: Fixed extraction filter bypass that allowed linking outside extraction directory (bsc#1244060) * CVE-2025-4435: Fixed Tarfile extracts filtered members when errorlevel=0 (bsc#1244061) * CVE-2025-4517: Fixed arbitrary filesystem writes outside the extraction directory during extraction with filter="data" (bsc#1244032) * CVE-2025-6069: Fixed worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705) * CVE-2025-8194: Fixed denial of service caused by tar archives with negative offsets (bsc#1247249) Other fixes: \- Limit buffer size for IPv6 address parsing (bsc#1244401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patchSUSE-2025-2778=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2778=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2778=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2778=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2778=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2778=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2778=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2778=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2778=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-2778=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-2778=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-2778=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2778=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2778=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2778=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2778=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-2778=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2778=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patchSUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2778=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-2778=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2778=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2778=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-2778=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-2778=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-2778=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-2778=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2778=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2778=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-testsuite-debuginfo-3.6.15-150300.10.97.1 * python3-devel-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-doc-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-testsuite-3.6.15-150300.10.97.1 * python3-tools-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-doc-devhelp-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 *python3-tk-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * openSUSE Leap 15.3 (x86_64) * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-32bit-3.6.15-150300.10.97.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libpython3_6m1_0-64bit-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-64bit-3.6.15-150300.10.97.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-debuginfo-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-testsuite-debuginfo-3.6.15-150300.10.97.1 * python3-devel-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-doc-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-testsuite-3.6.15-150300.10.97.1 * python3-tools-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-doc-devhelp-3.6.15-150300.10.97.1 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * openSUSE Leap 15.6 (x86_64) * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-32bit-3.6.15-150300.10.97.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 *python3-base-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 *python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-tools-3.6.15-150300.10.97.1 * python3-core-debugsource-3.6.15-150300.10.97.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-tools-3.6.15-150300.10.97.1 * python3-core-debugsource-3.6.15-150300.10.97.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 *python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 *python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 *python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 *python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Manager Proxy 4.3 (x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 *python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Manager Retail Branch Server 4.3 (x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 *libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python3-dbm-debuginfo-3.6.15-150300.10.97.2 * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-tools-3.6.15-150300.10.97.1 * python3-curses-debuginfo-3.6.15-150300.10.97.2 * python3-devel-3.6.15-150300.10.97.1 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-curses-3.6.15-150300.10.97.2 * python3-tk-debuginfo-3.6.15-150300.10.97.2 * python3-idle-3.6.15-150300.10.97.2 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * python3-devel-debuginfo-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * python3-tk-3.6.15-150300.10.97.2 * python3-dbm-3.6.15-150300.10.97.2 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * python3-debuginfo-3.6.15-150300.10.97.2 * python3-core-debugsource-3.6.15-150300.10.97.1 * python3-debugsource-3.6.15-150300.10.97.2 * python3-base-debuginfo-3.6.15-150300.10.97.1 * python3-3.6.15-150300.10.97.2 * libpython3_6m1_0-3.6.15-150300.10.97.1 * python3-base-3.6.15-150300.10.97.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.97.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12718.html * https://www.suse.com/security/cve/CVE-2025-4138.html *https://www.suse.com/security/cve/CVE-2025-4330.html * https://www.suse.com/security/cve/CVE-2025-4435.html * https://www.suse.com/security/cve/CVE-2025-4516.html * https://www.suse.com/security/cve/CVE-2025-4517.html * https://www.suse.com/security/cve/CVE-2025-6069.html * https://www.suse.com/security/cve/CVE-2025-8194.html * https://bugzilla.suse.com/show_bug.cgi?id=1233012 * https://bugzilla.suse.com/show_bug.cgi?id=1243273 * https://bugzilla.suse.com/show_bug.cgi?id=1244032 * https://bugzilla.suse.com/show_bug.cgi?id=1244056 * https://bugzilla.suse.com/show_bug.cgi?id=1244059 * https://bugzilla.suse.com/show_bug.cgi?id=1244060 * https://bugzilla.suse.com/show_bug.cgi?id=1244061 * https://bugzilla.suse.com/show_bug.cgi?id=1244401 * https://bugzilla.suse.com/show_bug.cgi?id=1244705 * https://bugzilla.suse.com/show_bug.cgi?id=1247249 * https://bugzilla.suse.com/show_bug.cgi?id=831629 . SUSE enhances python3 to resolve various vulnerabilities, tackling security threats such as denial of service and data leakage risks.. SUSE python3 security important update. . Severity: Important. LinuxSecurity.com Team
* bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059 . # Security update for python36 Announcement ID: SUSE-SU-2025:02297-1 Release Date: 2025-07-11T16:03:57Z Rating: important References: * bsc#1233012 * bsc#1243273 * bsc#1244032 * bsc#1244056 * bsc#1244059 * bsc#1244060 * bsc#1244061 * bsc#1244401 * bsc#1244705 Cross-References: * CVE-2024-12718 * CVE-2025-4138 * CVE-2025-4330 * CVE-2025-4435 * CVE-2025-4516 * CVE-2025-4517 * CVE-2025-6069 CVSS scores: * CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-12718 ( NVD ): 10.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-12718 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-4138 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2025-4138 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4330 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4435 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4435 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-4516 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-4516 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4516 ( NVD ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-4517 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities and has two security fixes can now be installed. ## Description: This update for python36 fixes the following issues: * CVE-2024-12718: Fixed extraction filter bypass that allowed file metadata modification outside extraction directory (bsc#1244056) * CVE-2025-4138: Fixed issue that might allow symlink targets to point outside the destination directory, and the modification of some file metadata (bsc#1244059) * CVE-2025-4330: Fixed extraction filter bypass that allowed linking outside extraction directory (bsc#1244060) * CVE-2025-4435: Fixed Tarfile extracts filtered members when errorlevel=0 (bsc#1244061) * CVE-2025-4516: Fixed denial of service due to DecodeError handling vulnerability (bsc#1243273) * CVE-2025-4517: Fixed arbitrary filesystem writes outside the extraction directory during extraction with filter="data" (bsc#1244032) * CVE-2025-6069: Fixed worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705) Other fixes: \- Add python36-* provides/obsoletes to enable SLE-12 -> SLE-15 migration (bsc#1233012) \- Update vendored ipaddress module to 3.8 equivalent \- Limit buffer size for IPv6 address parsing (bsc#1244401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or"zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-2297=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2297=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python36-devel-3.6.15-84.1 * libpython3_6m1_0-3.6.15-84.1 * python36-debugsource-3.6.15-84.1 * python36-3.6.15-84.1 * python36-debuginfo-3.6.15-84.1 * python36-base-3.6.15-84.1 * libpython3_6m1_0-debuginfo-3.6.15-84.1 * python36-base-debuginfo-3.6.15-84.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libpython3_6m1_0-debuginfo-32bit-3.6.15-84.1 * libpython3_6m1_0-32bit-3.6.15-84.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpython3_6m1_0-debuginfo-32bit-3.6.15-84.1 * python36-devel-3.6.15-84.1 * libpython3_6m1_0-3.6.15-84.1 * python36-debugsource-3.6.15-84.1 * python36-3.6.15-84.1 * libpython3_6m1_0-32bit-3.6.15-84.1 * python36-debuginfo-3.6.15-84.1 * python36-base-3.6.15-84.1 * libpython3_6m1_0-debuginfo-3.6.15-84.1 * python36-base-debuginfo-3.6.15-84.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12718.html * https://www.suse.com/security/cve/CVE-2025-4138.html * https://www.suse.com/security/cve/CVE-2025-4330.html * https://www.suse.com/security/cve/CVE-2025-4435.html * https://www.suse.com/security/cve/CVE-2025-4516.html * https://www.suse.com/security/cve/CVE-2025-4517.html * https://www.suse.com/security/cve/CVE-2025-6069.html * https://bugzilla.suse.com/show_bug.cgi?id=1233012 * https://bugzilla.suse.com/show_bug.cgi?id=1243273 * https://bugzilla.suse.com/show_bug.cgi?id=1244032 * https://bugzilla.suse.com/show_bug.cgi?id=1244056 * https://bugzilla.suse.com/show_bug.cgi?id=1244059 *https://bugzilla.suse.com/show_bug.cgi?id=1244060 * https://bugzilla.suse.com/show_bug.cgi?id=1244061 * https://bugzilla.suse.com/show_bug.cgi?id=1244401 * https://bugzilla.suse.com/show_bug.cgi?id=1244705 . The recent python36 patch from SUSE deals with various security vulnerabilities; vital for maintaining the security and reliability of your systems. Take action now!. SUSE Linux, python36 security, package updates, file extraction issues. . Severity: Important. LinuxSecurity.com Team
Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter="data" and filter="tar") to be bypassed using crafted symlinks and hard links.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3436f3d2b4 2025-06-14 01:51:14.531294+00:00 -------------------------------------------------------------------------------- Name : python3.12 Product : Fedora 41 Version : 3.12.11 Release : 1.fc41 URL : https://www.python.org/ Summary : Version 3.12 of the Python interpreter Description : Python 3.12 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.12 package provides the "python3.12" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.12-libs package, which should be installed automatically along with python3.12. The remaining parts of the Python standard library are broken out into the python3.12-tkinter and python3.12-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.12-docs package. Packages containing additional libraries for Python are generally named with the "python3.12-" prefix. -------------------------------------------------------------------------------- Update Information: Update to 3.12.11. gh-135034: [CVE 2024-12718] [CVE 2025-4138] [CVE 2025-4330] [CVE 2025-4435] [CVE 2025-4517] Fixes multiple issues that allowed tarfile extraction filters (filter="data" and filter="tar") to be bypassed using crafted symlinks and hard links. gh-133767: Fix use-after-free in the âunicode-escapeâ decoder with a non-âstrictâ error handler. gh-128840:Short-circuit the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 4 2025 Tomáš HrnÄiar - 3.12.11-1 - Update to 3.12.11 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3436f3d2b4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 41 rolls out python3.12.11 update addressing various tarfile extraction problems along with improved features.. python update, Fedora security, tarfile issues, Python 3.12, extraction security. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for ark ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0090-1 Rating: important References: #1236737 Cross-References: CVE-2024-57966 CVSS scores: CVE-2024-57966 (SUSE): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for ark fixes the following issues: - CVE-2024-57966: Disable extraction to absolute path from an archive (boo#1236737) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-90=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 ppc64le s390x x86_64): ark-23.08.5-bp156.2.3.1 libkerfuffle23-23.08.5-bp156.2.3.1 - openSUSE Backports SLE-15-SP6 (noarch): ark-lang-23.08.5-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2024-57966.html https://bugzilla.suse.com/1236737 . Addressing an important security issue in ark, openSUSE releases update openSUSE-SU-2025:0090-1.. update, security, fixes, vulnerability, opensuse. . Severity: Important. LinuxSecurity.com Team
A security issue exists in Ark where a maliciously crafted archive containing file paths beginning with "/" allows files to be extracted to locations outside the intended directory. References: . MGASA-2025-0061 - Updated ark packages fix security vulnerability Publication date: 13 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0061.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-57966 A security issue exists in Ark where a maliciously crafted archive containing file paths beginning with "/" allows files to be extracted to locations outside the intended directory. References: - https://bugs.mageia.org/show_bug.cgi?id=34013 - https://kde.org/info/security/advisory-20250207-1.txt - https://www.cve.org/CVERecord?id=CVE-2024-57966 SRPMS: - 9/core/ark-23.04.3-1.1.mga9 . Investigate the Mageia security notice MGASA-2025-0061 detailing a vulnerability in ark that permits unauthorized access for file extraction.. Mageia Ark Security Advisory, Path Extraction Issue, Malicious Archive Exploit. . Severity: Critical. LinuxSecurity.com Team
Upstream version 0.13.72 Fixes CVE-2020-18442. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-737e44718a 2022-02-18 01:36:49.249212 --------------------------------------------------------------------------------Name : zziplib Product : Fedora 35 Version : 0.13.72 Release : 1.fc35 URL : Summary : Lightweight library to easily extract data from zip files Description : The zziplib library is intentionally lightweight, it offers the ability to easily extract data from files archived in a single zip file. Applications can bundle files into a single zip archive and access them. The implementation is based only on the (free) subset of compression with the zlib algorithm which is actually used by the zip/unzip tools. --------------------------------------------------------------------------------Update Information: Upstream version 0.13.72 Fixes CVE-2020-18442 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 9 2022 Alexander Bokovoy - 0.13.72-1 - 0.13.72 - Fixes CVE-2020-18442 - Resolves: rhbz#1973831 - Switch build to CMake, drop 32-bit patches as checks integrated in CMake already --------------------------------------------------------------------------------References: [ 1 ] Bug #1973831 - CVE-2020-18442 zziplib: infinite loop via the return value of zzip_file_read() as used in unzzip_cat_file() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1973831 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-737e44718a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gstreamer-plugins-good ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2916-1 Rating: moderate References: #1184739 Cross-References: CVE-2021-3497 CVSS scores: CVE-2021-3497 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-3497 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gstreamer-plugins-good fixes the following issues: - CVE-2021-3497: Matroskademux: Fix extraction of multichannel WavPack (bsc#1184739). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-2916=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): gstreamer-plugins-good-1.8.3-16.3.1 gstreamer-plugins-good-debuginfo-1.8.3-16.3.1 gstreamer-plugins-good-debugsource-1.8.3-16.3.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): gstreamer-plugins-good-lang-1.8.3-16.3.1 References: https://www.suse.com/security/cve/CVE-2021-3497.html https://bugzilla.suse.com/1184739 . Patch addresses significant flaw in gstreamer-plugins-bad for SUSE, improving safety for its clients.. SUSE Security Update, Gstreamer Plugins, Patch Instructions, Security Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.