* bsc#1228165 * bsc#1231795 * bsc#1236705 Cross-References: . # Security update for python311 Announcement ID: SUSE-SU-2025:0551-1 Release Date: 2025-02-14T15:10:00Z Rating: moderate References: * bsc#1228165 * bsc#1231795 * bsc#1236705 Cross-References: * CVE-2025-0938 CVSS scores: * CVE-2025-0938 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N * CVE-2025-0938 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-0938 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2025-0938: domain names containing square brackets are not identified as incorrect by urlparse. (bsc#1236705) Other fixes: * Update to version 3.11.11. * Remove -IVendor/ from python-config. (bsc#1231795) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-551=1 openSUSE-SLE-15.6-2025-551=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-551=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2025-551=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * python311-idle-3.11.11-150600.3.16.2 *python311-debuginfo-3.11.11-150600.3.16.2 * python311-curses-debuginfo-3.11.11-150600.3.16.2 * libpython3_11-1_0-3.11.11-150600.3.16.2 * libpython3_11-1_0-debuginfo-3.11.11-150600.3.16.2 * python311-doc-3.11.11-150600.3.16.2 * python311-testsuite-debuginfo-3.11.11-150600.3.16.2 * python311-tools-3.11.11-150600.3.16.2 * python311-dbm-debuginfo-3.11.11-150600.3.16.2 * python311-3.11.11-150600.3.16.2 * python311-devel-3.11.11-150600.3.16.2 * python311-debugsource-3.11.11-150600.3.16.2 * python311-tk-3.11.11-150600.3.16.2 * python311-curses-3.11.11-150600.3.16.2 * python311-dbm-3.11.11-150600.3.16.2 * python311-testsuite-3.11.11-150600.3.16.2 * python311-doc-devhelp-3.11.11-150600.3.16.2 * python311-core-debugsource-3.11.11-150600.3.16.2 * python311-base-3.11.11-150600.3.16.2 * python311-tk-debuginfo-3.11.11-150600.3.16.2 * python311-base-debuginfo-3.11.11-150600.3.16.2 * openSUSE Leap 15.6 (x86_64) * python311-base-32bit-debuginfo-3.11.11-150600.3.16.2 * python311-base-32bit-3.11.11-150600.3.16.2 * python311-32bit-3.11.11-150600.3.16.2 * libpython3_11-1_0-32bit-debuginfo-3.11.11-150600.3.16.2 * libpython3_11-1_0-32bit-3.11.11-150600.3.16.2 * python311-32bit-debuginfo-3.11.11-150600.3.16.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libpython3_11-1_0-64bit-debuginfo-3.11.11-150600.3.16.2 * python311-64bit-3.11.11-150600.3.16.2 * libpython3_11-1_0-64bit-3.11.11-150600.3.16.2 * python311-base-64bit-debuginfo-3.11.11-150600.3.16.2 * python311-base-64bit-3.11.11-150600.3.16.2 * python311-64bit-debuginfo-3.11.11-150600.3.16.2 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python311-core-debugsource-3.11.11-150600.3.16.2 * python311-base-3.11.11-150600.3.16.2 * libpython3_11-1_0-3.11.11-150600.3.16.2 * libpython3_11-1_0-debuginfo-3.11.11-150600.3.16.2 * python311-base-debuginfo-3.11.11-150600.3.16.2 * Python 3 Module 15-SP6 (aarch64 ppc64le s390x x86_64) *python311-dbm-debuginfo-3.11.11-150600.3.16.2 * python311-3.11.11-150600.3.16.2 * python311-devel-3.11.11-150600.3.16.2 * python311-debugsource-3.11.11-150600.3.16.2 * python311-idle-3.11.11-150600.3.16.2 * python311-dbm-3.11.11-150600.3.16.2 * python311-tk-3.11.11-150600.3.16.2 * python311-debuginfo-3.11.11-150600.3.16.2 * python311-core-debugsource-3.11.11-150600.3.16.2 * python311-curses-3.11.11-150600.3.16.2 * python311-tk-debuginfo-3.11.11-150600.3.16.2 * python311-curses-debuginfo-3.11.11-150600.3.16.2 * python311-tools-3.11.11-150600.3.16.2 ## References: * https://www.suse.com/security/cve/CVE-2025-0938.html * https://bugzilla.suse.com/show_bug.cgi?id=1228165 * https://bugzilla.suse.com/show_bug.cgi?id=1231795 * https://bugzilla.suse.com/show_bug.cgi?id=1236705 . SUSE has released a security advisory regarding python311, pointing out middle-level concerns linked to the guidance for applying essential fixes.. Python Security, SUSE Advisory, OpenSUSE Update. . LinuxSecurity.com Team
* bsc#1236705 Cross-References: * CVE-2025-0938 . # Security update for python310 Announcement ID: SUSE-SU-2025:0406-1 Release Date: 2025-02-10T13:55:52Z Rating: moderate References: * bsc#1236705 Cross-References: * CVE-2025-0938 CVSS scores: * CVE-2025-0938 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N * CVE-2025-0938 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-0938 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for python310 fixes the following issues: * CVE-2025-0938: domain names containing square brackets are not identified as incorrect by urlparse. (bsc#1236705) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-406=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-406=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python310-tk-debuginfo-3.10.16-150400.4.69.1 * python310-devel-3.10.16-150400.4.69.1 * libpython3_10-1_0-3.10.16-150400.4.69.1 * python310-core-debugsource-3.10.16-150400.4.69.1 * python310-doc-3.10.16-150400.4.69.1 * python310-debuginfo-3.10.16-150400.4.69.1 * python310-base-debuginfo-3.10.16-150400.4.69.1 * python310-dbm-3.10.16-150400.4.69.1 * python310-doc-devhelp-3.10.16-150400.4.69.1 * python310-testsuite-debuginfo-3.10.16-150400.4.69.1 * python310-base-3.10.16-150400.4.69.1 * python310-debugsource-3.10.16-150400.4.69.1 * python310-tk-3.10.16-150400.4.69.1 * python310-dbm-debuginfo-3.10.16-150400.4.69.1 * python310-3.10.16-150400.4.69.1 * python310-curses-debuginfo-3.10.16-150400.4.69.1 * python310-curses-3.10.16-150400.4.69.1 * python310-idle-3.10.16-150400.4.69.1 * python310-tools-3.10.16-150400.4.69.1 * python310-testsuite-3.10.16-150400.4.69.1 * libpython3_10-1_0-debuginfo-3.10.16-150400.4.69.1 * openSUSE Leap 15.4 (x86_64) * python310-base-32bit-debuginfo-3.10.16-150400.4.69.1 * libpython3_10-1_0-32bit-3.10.16-150400.4.69.1 * libpython3_10-1_0-32bit-debuginfo-3.10.16-150400.4.69.1 * python310-base-32bit-3.10.16-150400.4.69.1 * python310-32bit-3.10.16-150400.4.69.1 * python310-32bit-debuginfo-3.10.16-150400.4.69.1 * openSUSE Leap 15.4 (aarch64_ilp32) * python310-64bit-debuginfo-3.10.16-150400.4.69.1 * libpython3_10-1_0-64bit-debuginfo-3.10.16-150400.4.69.1 * libpython3_10-1_0-64bit-3.10.16-150400.4.69.1 * python310-64bit-3.10.16-150400.4.69.1 * python310-base-64bit-debuginfo-3.10.16-150400.4.69.1 * python310-base-64bit-3.10.16-150400.4.69.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python310-tk-debuginfo-3.10.16-150400.4.69.1 * python310-devel-3.10.16-150400.4.69.1 * libpython3_10-1_0-3.10.16-150400.4.69.1 * python310-core-debugsource-3.10.16-150400.4.69.1 * python310-doc-3.10.16-150400.4.69.1 * python310-debuginfo-3.10.16-150400.4.69.1 * python310-base-debuginfo-3.10.16-150400.4.69.1 * python310-dbm-3.10.16-150400.4.69.1 * python310-doc-devhelp-3.10.16-150400.4.69.1 * python310-testsuite-debuginfo-3.10.16-150400.4.69.1 * python310-base-3.10.16-150400.4.69.1 * python310-debugsource-3.10.16-150400.4.69.1 * python310-tk-3.10.16-150400.4.69.1 * python310-dbm-debuginfo-3.10.16-150400.4.69.1 * python310-3.10.16-150400.4.69.1 * python310-curses-3.10.16-150400.4.69.1 * python310-curses-debuginfo-3.10.16-150400.4.69.1 * python310-idle-3.10.16-150400.4.69.1 * python310-tools-3.10.16-150400.4.69.1 * python310-testsuite-3.10.16-150400.4.69.1 * libpython3_10-1_0-debuginfo-3.10.16-150400.4.69.1 * openSUSE Leap 15.6 (x86_64) * python310-base-32bit-debuginfo-3.10.16-150400.4.69.1 * libpython3_10-1_0-32bit-3.10.16-150400.4.69.1 * libpython3_10-1_0-32bit-debuginfo-3.10.16-150400.4.69.1 * python310-base-32bit-3.10.16-150400.4.69.1 * python310-32bit-3.10.16-150400.4.69.1 * python310-32bit-debuginfo-3.10.16-150400.4.69.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0938.html * https://bugzilla.suse.com/show_bug.cgi?id=1236705 . An important Python 3.10 security patch addresses a domain name parsing bug in openSUSE Leap. Please upgrade without delay!. openSUSE python310 security moderate CVE fixes. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8836 http://linux.oracle.com/errata/ELSA-2024-8836.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: python3.12-3.12.6-1.el8_10.x86_64.rpm python3.12-3.12.6-1.el8_10.i686.rpm python3.12-devel-3.12.6-1.el8_10.i686.rpm python3.12-devel-3.12.6-1.el8_10.x86_64.rpm python3.12-libs-3.12.6-1.el8_10.i686.rpm python3.12-libs-3.12.6-1.el8_10.x86_64.rpm python3.12-rpm-macros-3.12.6-1.el8_10.noarch.rpm python3.12-tkinter-3.12.6-1.el8_10.x86_64.rpm python3.12-debug-3.12.6-1.el8_10.i686.rpm python3.12-debug-3.12.6-1.el8_10.x86_64.rpm python3.12-idle-3.12.6-1.el8_10.i686.rpm python3.12-idle-3.12.6-1.el8_10.x86_64.rpm python3.12-test-3.12.6-1.el8_10.i686.rpm python3.12-test-3.12.6-1.el8_10.x86_64.rpm python3.12-tkinter-3.12.6-1.el8_10.i686.rpm aarch64: python3.12-3.12.6-1.el8_10.aarch64.rpm python3.12-devel-3.12.6-1.el8_10.aarch64.rpm python3.12-libs-3.12.6-1.el8_10.aarch64.rpm python3.12-rpm-macros-3.12.6-1.el8_10.noarch.rpm python3.12-tkinter-3.12.6-1.el8_10.aarch64.rpm python3.12-debug-3.12.6-1.el8_10.aarch64.rpm python3.12-idle-3.12.6-1.el8_10.aarch64.rpm python3.12-test-3.12.6-1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//python3.12-3.12.6-1.el8_10.src.rpm Related CVEs: CVE-2024-6232 Description of changes: [3.12.6-1] - Update to 3.12.6 Resolves: RHEL-57405 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8359 http://linux.oracle.com/errata/ELSA-2024-8359.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: python39-3.9.20-1.module+el8.10.0+90419+54594e05.x86_64.rpm python39-cffi-1.14.3-2.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-chardet-3.0.4-19.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-cryptography-3.3.1-3.0.1.module+el8.10.0+90269+2fa22b99.x86_64.rpm python39-debug-3.9.20-1.module+el8.10.0+90419+54594e05.x86_64.rpm python39-devel-3.9.20-1.module+el8.10.0+90419+54594e05.x86_64.rpm python39-idle-3.9.20-1.module+el8.10.0+90419+54594e05.x86_64.rpm python39-idna-2.10-4.module+el8.10.0+90341+71ca88f4.noarch.rpm python39-libs-3.9.20-1.module+el8.10.0+90419+54594e05.x86_64.rpm python39-lxml-4.6.5-1.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-mod_wsgi-4.7.1-7.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-numpy-1.19.4-3.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-numpy-doc-1.19.4-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-numpy-f2py-1.19.4-3.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-pip-20.2.4-9.module+el8.10.0+90269+2fa22b99.noarch.rpm python39-pip-wheel-20.2.4-9.module+el8.10.0+90269+2fa22b99.noarch.rpm python39-ply-3.11-10.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-psutil-5.8.0-4.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-psycopg2-2.8.6-3.module+el8.10.0+90269+2fa22b99.x86_64.rpm python39-psycopg2-doc-2.8.6-3.module+el8.10.0+90269+2fa22b99.x86_64.rpm python39-psycopg2-tests-2.8.6-3.module+el8.10.0+90269+2fa22b99.x86_64.rpm python39-pycparser-2.20-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-PyMySQL-0.10.1-2.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-pysocks-1.7.1-4.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-pyyaml-5.4.1-1.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-requests-2.25.0-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-rpm-macros-3.9.20-1.module+el8.10.0+90419+54594e05.noarch.rpm python39-scipy-1.5.4-5.module+el8.9.0+90016+9c2d6573.x86_64.rpm python39-setuptools-50.3.2-6.module+el8.10.0+90395+b6c4aad1.noarch.rpm python39-setuptools-wheel-50.3.2-6.module+el8.10.0+90395+b6c4aad1.noarch.rpm python39-six-1.15.0-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-test-3.9.20-1.module+el8.10.0+90419+54594e05.x86_64.rpm python39-tkinter-3.9.20-1.module+el8.10.0+90419+54594e05.x86_64.rpm python39-toml-0.10.1-5.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-urllib3-1.25.10-5.module+el8.10.0+90269+2fa22b99.noarch.rpm python39-wheel-0.35.1-4.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-wheel-wheel-0.35.1-4.module+el8.9.0+90016+9c2d6573.noarch.rpm aarch64: python39-3.9.20-1.module+el8.10.0+90419+54594e05.aarch64.rpm python39-cffi-1.14.3-2.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-chardet-3.0.4-19.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-cryptography-3.3.1-3.0.1.module+el8.10.0+90269+2fa22b99.aarch64.rpm python39-debug-3.9.20-1.module+el8.10.0+90419+54594e05.aarch64.rpm python39-devel-3.9.20-1.module+el8.10.0+90419+54594e05.aarch64.rpm python39-idle-3.9.20-1.module+el8.10.0+90419+54594e05.aarch64.rpm python39-idna-2.10-4.module+el8.10.0+90341+71ca88f4.noarch.rpm python39-libs-3.9.20-1.module+el8.10.0+90419+54594e05.aarch64.rpm python39-lxml-4.6.5-1.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-mod_wsgi-4.7.1-7.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-numpy-1.19.4-3.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-numpy-doc-1.19.4-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-numpy-f2py-1.19.4-3.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-pip-20.2.4-9.module+el8.10.0+90269+2fa22b99.noarch.rpm python39-pip-wheel-20.2.4-9.module+el8.10.0+90269+2fa22b99.noarch.rpm python39-ply-3.11-10.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-psutil-5.8.0-4.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-psycopg2-2.8.6-3.module+el8.10.0+90269+2fa22b99.aarch64.rpm python39-psycopg2-doc-2.8.6-3.module+el8.10.0+90269+2fa22b99.aarch64.rpm python39-psycopg2-tests-2.8.6-3.module+el8.10.0+90269+2fa22b99.aarch64.rpm python39-pycparser-2.20-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-PyMySQL-0.10.1-2.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-pysocks-1.7.1-4.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-pyyaml-5.4.1-1.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-requests-2.25.0-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-rpm-macros-3.9.20-1.module+el8.10.0+90419+54594e05.noarch.rpm python39-scipy-1.5.4-5.module+el8.9.0+90016+9c2d6573.aarch64.rpm python39-setuptools-50.3.2-6.module+el8.10.0+90395+b6c4aad1.noarch.rpm python39-setuptools-wheel-50.3.2-6.module+el8.10.0+90395+b6c4aad1.noarch.rpm python39-six-1.15.0-3.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-test-3.9.20-1.module+el8.10.0+90419+54594e05.aarch64.rpm python39-tkinter-3.9.20-1.module+el8.10.0+90419+54594e05.aarch64.rpm python39-toml-0.10.1-5.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-urllib3-1.25.10-5.module+el8.10.0+90269+2fa22b99.noarch.rpm python39-wheel-0.35.1-4.module+el8.9.0+90016+9c2d6573.noarch.rpm python39-wheel-wheel-0.35.1-4.module+el8.9.0+90016+9c2d6573.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//mod_wsgi-4.7.1-7.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//numpy-1.19.4-3.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python39-3.9.20-1.module+el8.10.0+90419+54594e05.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python3x-pip-20.2.4-9.module+el8.10.0+90269+2fa22b99.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python3x-setuptools-50.3.2-6.module+el8.10.0+90395+b6c4aad1.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python3x-six-1.15.0-3.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-cffi-1.14.3-2.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-chardet-3.0.4-19.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-cryptography-3.3.1-3.0.1.module+el8.10.0+90269+2fa22b99.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-idna-2.10-4.module+el8.10.0+90341+71ca88f4.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-lxml-4.6.5-1.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-ply-3.11-10.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-psutil-5.8.0-4.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-psycopg2-2.8.6-3.module+el8.10.0+90269+2fa22b99.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-pycparser-2.20-3.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-PyMySQL-0.10.1-2.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-pysocks-1.7.1-4.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-requests-2.25.0-3.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-toml-0.10.1-5.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-urllib3-1.25.10-5.module+el8.10.0+90269+2fa22b99.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-wheel-0.35.1-4.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//PyYAML-5.4.1-1.module+el8.9.0+90016+9c2d6573.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//scipy-1.5.4-5.module+el8.9.0+90016+9c2d6573.src.rpm Related CVEs: CVE-2024-6232 Description of changes: mod_wsgi numpy python39 [3.9.20-1] - Update to 3.9.20 Resolves: RHEL-60007 python3x-pip python3x-setuptools python3x-six python-cffi python-chardet python-cryptography python-idna python-lxml python-ply python-psutil python-psycopg2 python-pycparser python-PyMySQL python-pysocks python-requests python-toml python-urllib3 python-wheel PyYAML scipy _______________________________________________ El-errata mailing list
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2467-1 Container Tags : bci/python:3 , bci/python:3.10 , bci/python:3.10-5.42 , bci/python:latest Container Release : 5.42 Severity : important Type : security References : 1202624 1203125 1203438 CVE-2020-10735 CVE-2021-28861 CVE-2022-40674 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3473-1 Released: Fri Sep 30 10:33:55 2022 Summary: Security update for python310 Type: security Severity: important References: 1202624,1203125,CVE-2020-10735,CVE-2021-28861 This update for python310 fixes the following issues: Updated to version 3.10.7: - CVE-2020-10735: Fixed DoS due to missing limit of amount of digits when converting text to int (bsc#1203125). - CVE-2021-28861: Fixed an open redirect in the http server when an URI path starts with // (bsc#1202624). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3489-1 Released: Sat Oct 1 13:35:24 2022 Summary: Security update for expat Type: security Severity: important References: 1203438,CVE-2022-40674 This update for expat fixes the following issues: - CVE-2022-40674: Fixed use-after-free in the doContent function in xmlparse.c (bsc#1203438). The following package changes have been done: - libexpat1-2.4.4-150400.3.9.1 updated - libpython3_10-1_0-3.10.7-150400.4.10.1 updated - python310-base-3.10.7-150400.4.10.1 updated - python310-3.10.7-150400.4.10.1 updated - aaa_base-84.87+git20180409.04c9dae-3.57.1 removed - bash-4.4-150400.25.22 removed - bash-sh-4.4-150400.25.22 removed -ca-certificates-2+git20210309.21162a6-2.1 removed - coreutils-8.32-150400.7.5 removed - cpio-2.13-150400.1.98 removed - cracklib-2.9.7-11.6.1 removed - cracklib-dict-small-2.9.7-11.6.1 removed - crypto-policies-20210917.c9d86d1-150400.1.7 removed - curl-7.79.1-150400.5.6.1 removed - diffutils-3.6-4.3.1 removed - file-magic-5.32-7.14.1 removed - filesystem-15.0-11.8.1 removed - fillup-1.42-2.18 removed - findutils-4.8.0-1.20 removed - glibc-2.31-150300.41.1 removed - grep-3.1-150000.4.6.1 removed - info-6.5-4.17 removed - krb5-1.19.2-150400.1.9 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libaudit1-3.0.6-150400.2.13 removed - libblkid1-2.37.2-150400.8.3.1 removed - libbrotlicommon1-1.0.7-3.3.1 removed - libbrotlidec1-1.0.7-3.3.1 removed - libbz2-1-1.0.8-150400.1.122 removed - libcap-ng0-0.7.9-4.37 removed - libcap2-2.63-150400.1.7 removed - libcom_err2-1.46.4-150400.3.3.1 removed - libcrack2-2.9.7-11.6.1 removed - libcrypt1-4.4.15-150300.4.4.3 removed - libcurl4-7.79.1-150400.5.6.1 removed - libdw1-0.185-150400.5.3.1 removed - libeconf0-0.4.4+git20220104.962774f-150400.1.38 removed - libelf1-0.185-150400.5.3.1 removed - libfdisk1-2.37.2-150400.8.3.1 removed - libffi7-3.2.1.git259-10.8 removed - libgcc_s1-11.3.0+git1637-150000.1.11.2 removed - libgcrypt20-1.9.4-150400.4.6 removed - libgcrypt20-hmac-1.9.4-150400.4.6 removed - libgmp10-6.1.2-4.9.1 removed - libgpg-error0-1.42-150400.1.101 removed - libidn2-0-2.2.0-3.6.1 removed - libkeyutils1-1.6.3-5.6.1 removed - libldap-2_4-2-2.4.46-150200.14.11.2 removed - libldap-data-2.4.46-150200.14.11.2 removed - liblua5_3-5-5.3.6-3.6.1 removed - liblz4-1-1.9.3-150400.1.7 removed - liblzma5-5.2.3-150000.4.7.1 removed - libmagic1-5.32-7.14.1 removed - libmount1-2.37.2-150400.8.3.1 removed - libncurses6-6.1-150000.5.12.1 removed - libnghttp2-14-1.40.0-6.1 removed - libnsl2-1.2.0-2.44 removed - libopenssl1_1-1.1.1l-150400.7.7.1 removed - libopenssl1_1-hmac-1.1.1l-150400.7.7.1 removed - libp11-kit0-0.23.22-150400.1.10 removed -libpcre1-8.45-150000.20.13.1 removed - libpopt0-1.16-3.22 removed - libpsl5-0.20.1-150000.3.3.1 removed - libreadline7-7.0-150400.25.22 removed - libsasl2-3-2.1.27-150300.4.6.1 removed - libselinux1-3.1-150400.1.69 removed - libsemanage1-3.1-150400.1.65 removed - libsepol1-3.1-150400.1.70 removed - libsmartcols1-2.37.2-150400.8.3.1 removed - libsqlite3-0-3.39.3-150000.3.17.1 removed - libssh-config-0.9.6-150400.1.5 removed - libssh4-0.9.6-150400.1.5 removed - libstdc++6-11.3.0+git1637-150000.1.11.2 removed - libsystemd0-249.12-150400.8.10.1 removed - libtasn1-4.13-4.5.1 removed - libtasn1-6-4.13-4.5.1 removed - libtirpc-netconfig-1.2.6-150300.3.14.1 removed - libtirpc3-1.2.6-150300.3.14.1 removed - libudev1-249.12-150400.8.10.1 removed - libunistring2-0.9.10-1.1 removed - libutempter0-1.1.6-3.42 removed - libuuid1-2.37.2-150400.8.3.1 removed - libverto1-0.2.6-3.20 removed - libxml2-2-2.9.14-150400.5.7.1 removed - libz1-1.2.11-150000.3.33.1 removed - libzio1-1.06-2.20 removed - libzstd1-1.5.0-150400.1.71 removed - login_defs-4.8.1-150400.8.57 removed - ncurses-utils-6.1-150000.5.12.1 removed - openssl-1_1-1.1.1l-150400.7.7.1 removed - p11-kit-0.23.22-150400.1.10 removed - p11-kit-tools-0.23.22-150400.1.10 removed - pam-1.3.0-150000.6.58.3 removed - patterns-base-fips-20200124-150400.18.4 removed - perl-base-5.26.1-150300.17.11.1 removed - permissions-20201225-150400.5.11.1 removed - rpm-config-SUSE-1-150400.14.3.1 removed - rpm-ndb-4.14.3-150300.49.1 removed - sed-4.4-11.6 removed - shadow-4.8.1-150400.8.57 removed - sles-release-15.4-150400.55.1 removed - system-group-hardware-20170617-150400.22.33 removed - system-user-root-20190513-3.3.1 removed - sysuser-shadow-3.1-150400.1.35 removed - terminfo-base-6.1-150000.5.12.1 removed - timezone-2022a-150000.75.10.1 removed - util-linux-2.37.2-150400.8.3.1 removed . Essential security patches for bci/python container enhance resilience against DoS attacks and various other vulnerabilities.. Container Security, Python Updates, SUSE Advisories, Patch Management. .Severity: Important. LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:823-1 Container Tags : bci/python:3 , bci/python:3.9 , bci/python:3.9-15.6 , bci/python:latest Container Release : 15.6 Severity : moderate Type : security References : 1183533 1193489 CVE-2021-28153 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1451-1 Released: Thu Apr 28 10:47:22 2022 Summary: Recommended update for perl Type: recommended Severity: moderate References: 1193489 This update for perl fixes the following issues: - Fix Socket::VERSION evaluation and stabilize Socket:VERSION comparisons (bsc#1193489) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1455-1 Released: Thu Apr 28 11:31:51 2022 Summary: Security update for glib2 Type: security Severity: low References: 1183533,CVE-2021-28153 This update for glib2 fixes the following issues: - CVE-2021-28153: Fixed an issue where symlink targets would be incorrectly created as empty files (bsc#1183533). The following package changes have been done: - libglib-2_0-0-2.62.6-150200.3.9.1 updated - perl-base-5.26.1-150300.17.3.1 updated - container:sles15-image-15.0.0-17.14.6 updated . SUSE container update featuring enhancements for bci/python, incorporating details of moderate security advisories as well.. bci/python update, SUSE advisory, container security, python patches. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.