Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves five vulnerabilities and has one security fix can now be installed.. # Security update for python310 Announcement ID: SUSE-SU-2026:1947-1 Release Date: 2026-05-18T07:49:36Z Rating: important References: * bsc#1258364 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262654 Cross-References: * CVE-2026-1502 * CVE-2026-3446 * CVE-2026-4786 * CVE-2026-6019 * CVE-2026-6100 CVSS scores: * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N *CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities and has one security fix can now be installed. ## Description: This update for python310 fixes the following issues Security issues: * CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969). * CVE-2026-3446: base64 decoding stops at first padded quad by default (bsc#1261970). * CVE-2026-4786: incomplete mitigation of , %action expansion for command injection to webbrowser.open() (bsc#1262319). * CVE-2026-6019: `BaseCookie.js_output()` does not neutralize characters in cookie values embedded in JS (bsc#1262654). * CVE-2026-6100: arbitrary code execution or information disclosure via use- after-free in decompression modules (bsc#1262098). Non security issue: * Conflicts between different versions of Python (bsc#1258364). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: *openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1947=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1947=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1947=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1947=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1947=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python310-tools-3.10.20-150400.4.112.1 * python310-core-debugsource-3.10.20-150400.4.112.1 * python310-dbm-debuginfo-3.10.20-150400.4.112.1 * python310-tk-3.10.20-150400.4.112.1 * python310-dbm-3.10.20-150400.4.112.1 * python310-tk-debuginfo-3.10.20-150400.4.112.1 * python310-doc-3.10.20-150400.4.112.1 * python310-testsuite-3.10.20-150400.4.112.1 * python310-doc-devhelp-3.10.20-150400.4.112.1 * python310-devel-3.10.20-150400.4.112.1 * python310-debugsource-3.10.20-150400.4.112.1 * python310-testsuite-debuginfo-3.10.20-150400.4.112.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.112.1 * python310-curses-debuginfo-3.10.20-150400.4.112.1 * libpython3_10-1_0-3.10.20-150400.4.112.1 * python310-base-debuginfo-3.10.20-150400.4.112.1 * python310-base-3.10.20-150400.4.112.1 * python310-idle-3.10.20-150400.4.112.1 * python310-3.10.20-150400.4.112.1 * python310-debuginfo-3.10.20-150400.4.112.1 * python310-curses-3.10.20-150400.4.112.1 * openSUSE Leap 15.4 (x86_64) * python310-base-32bit-debuginfo-3.10.20-150400.4.112.1 * python310-32bit-debuginfo-3.10.20-150400.4.112.1 * python310-32bit-3.10.20-150400.4.112.1 * libpython3_10-1_0-32bit-3.10.20-150400.4.112.1 * libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.112.1 * python310-base-32bit-3.10.20-150400.4.112.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_10-1_0-64bit-3.10.20-150400.4.112.1 * python310-64bit-debuginfo-3.10.20-150400.4.112.1 * python310-base-64bit-3.10.20-150400.4.112.1 * python310-base-64bit-debuginfo-3.10.20-150400.4.112.1 * python310-64bit-3.10.20-150400.4.112.1 * libpython3_10-1_0-64bit-debuginfo-3.10.20-150400.4.112.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python310-dbm-debuginfo-3.10.20-150400.4.112.1 * python310-dbm-3.10.20-150400.4.112.1 * python310-tk-3.10.20-150400.4.112.1 * python310-tk-debuginfo-3.10.20-150400.4.112.1 * python310-curses-debuginfo-3.10.20-150400.4.112.1 * python310-3.10.20-150400.4.112.1 * libpython3_10-1_0-3.10.20-150400.4.112.1 * python310-base-debuginfo-3.10.20-150400.4.112.1 * python310-idle-3.10.20-150400.4.112.1 * python310-devel-3.10.20-150400.4.112.1 * python310-tools-3.10.20-150400.4.112.1 * python310-debuginfo-3.10.20-150400.4.112.1 * python310-base-3.10.20-150400.4.112.1 * python310-core-debugsource-3.10.20-150400.4.112.1 * python310-debugsource-3.10.20-150400.4.112.1 * python310-curses-3.10.20-150400.4.112.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.112.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python310-dbm-debuginfo-3.10.20-150400.4.112.1 * python310-dbm-3.10.20-150400.4.112.1 * python310-tk-3.10.20-150400.4.112.1 * python310-tk-debuginfo-3.10.20-150400.4.112.1 * python310-curses-debuginfo-3.10.20-150400.4.112.1 * python310-3.10.20-150400.4.112.1 * libpython3_10-1_0-3.10.20-150400.4.112.1 * python310-base-debuginfo-3.10.20-150400.4.112.1 * python310-idle-3.10.20-150400.4.112.1 * python310-devel-3.10.20-150400.4.112.1 * python310-tools-3.10.20-150400.4.112.1 * python310-debuginfo-3.10.20-150400.4.112.1 * python310-base-3.10.20-150400.4.112.1 * python310-core-debugsource-3.10.20-150400.4.112.1 *python310-debugsource-3.10.20-150400.4.112.1 * python310-curses-3.10.20-150400.4.112.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.112.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python310-dbm-debuginfo-3.10.20-150400.4.112.1 * python310-dbm-3.10.20-150400.4.112.1 * python310-tk-3.10.20-150400.4.112.1 * python310-tk-debuginfo-3.10.20-150400.4.112.1 * python310-curses-debuginfo-3.10.20-150400.4.112.1 * python310-3.10.20-150400.4.112.1 * libpython3_10-1_0-3.10.20-150400.4.112.1 * python310-base-debuginfo-3.10.20-150400.4.112.1 * python310-idle-3.10.20-150400.4.112.1 * python310-tools-3.10.20-150400.4.112.1 * python310-devel-3.10.20-150400.4.112.1 * python310-debuginfo-3.10.20-150400.4.112.1 * python310-base-3.10.20-150400.4.112.1 * python310-core-debugsource-3.10.20-150400.4.112.1 * python310-debugsource-3.10.20-150400.4.112.1 * python310-curses-3.10.20-150400.4.112.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.112.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python310-dbm-debuginfo-3.10.20-150400.4.112.1 * python310-dbm-3.10.20-150400.4.112.1 * python310-tk-3.10.20-150400.4.112.1 * python310-tk-debuginfo-3.10.20-150400.4.112.1 * python310-curses-debuginfo-3.10.20-150400.4.112.1 * python310-3.10.20-150400.4.112.1 * libpython3_10-1_0-3.10.20-150400.4.112.1 * python310-base-debuginfo-3.10.20-150400.4.112.1 * python310-idle-3.10.20-150400.4.112.1 * python310-devel-3.10.20-150400.4.112.1 * python310-tools-3.10.20-150400.4.112.1 * python310-debuginfo-3.10.20-150400.4.112.1 * python310-base-3.10.20-150400.4.112.1 * python310-core-debugsource-3.10.20-150400.4.112.1 * python310-debugsource-3.10.20-150400.4.112.1 * python310-curses-3.10.20-150400.4.112.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.112.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1502.html *https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://bugzilla.suse.com/show_bug.cgi?id=1258364 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 . Critical update for python310 resolves five security issues and vulnerabilities in openSUSE, enhancing system protection.. python310 security fix, openSUSE vulnerabilities, important python310 advisory, software patch update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # python310-3.10.20-5.1 on GA media Announcement ID: openSUSE-SU-2026:10579-1 Rating: moderate Cross-References: * CVE-2026-3446 CVSS scores: * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python310-3.10.20-5.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python310 3.10.20-5.1 * python310-curses 3.10.20-5.1 * python310-dbm 3.10.20-5.1 * python310-idle 3.10.20-5.1 * python310-tk 3.10.20-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3446.html . Update for python310 resolves a moderate security issue on openSUSE Tumbleweed with CVE-2026-3446.. python310 security update, openSUSE Tumbleweed, CVE-2026-3446. . LinuxSecurity.com Team
An update that solves five vulnerabilities can now be installed.. # Security update for python310 Announcement ID: SUSE-SU-2026:1376-1 Release Date: 2026-04-15T19:07:00Z Rating: important References: * bsc#1259611 * bsc#1259734 * bsc#1259735 * bsc#1259989 * bsc#1260026 Cross-References: * CVE-2025-13462 * CVE-2026-3479 * CVE-2026-3644 * CVE-2026-4224 * CVE-2026-4519 CVSS scores: * CVE-2025-13462 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-13462 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13462 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3644 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3644 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3644 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4224 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-4224 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4224 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4519 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N * CVE-2026-4519 ( SUSE ): 6.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N * CVE-2026-4519 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for python310 fixes the following issues: * CVE-2025-13462: incorrect parsing of TarInfo when GNU long name and type AREGTYPE are combined can lead to misinterpretation of tar archives (bsc#1259611). * CVE-2026-3479: improper resource argument validation in `pkgutil.get_data()` can lead to path traversal (bsc#1259989). * CVE-2026-3644: incomplete control character validation in http.cookies can lead to input validation bypass (bsc#1259734). * CVE-2026-4224: parsing XML with deeply nested DTD content models can lead to C stack overflow (bsc#1259735). * CVE-2026-4519: failure to sanitize leading dashes in URLs in the `webbrowser.open()` API can lead to web browser command line option injection (bsc#1260026). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1376=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-1376=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1376=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1376=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1376=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1376=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python310-tk-debuginfo-3.10.20-150400.4.107.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.107.1 * python310-testsuite-3.10.20-150400.4.107.1 * python310-doc-3.10.20-150400.4.107.1 * python310-base-3.10.20-150400.4.107.1 * python310-doc-devhelp-3.10.20-150400.4.107.1 * python310-dbm-debuginfo-3.10.20-150400.4.107.1 * python310-core-debugsource-3.10.20-150400.4.107.1 * python310-debuginfo-3.10.20-150400.4.107.1 * python310-curses-3.10.20-150400.4.107.1 * python310-tools-3.10.20-150400.4.107.1 * python310-idle-3.10.20-150400.4.107.1 * libpython3_10-1_0-3.10.20-150400.4.107.1 * python310-testsuite-debuginfo-3.10.20-150400.4.107.1 * python310-debugsource-3.10.20-150400.4.107.1 * python310-curses-debuginfo-3.10.20-150400.4.107.1 * python310-dbm-3.10.20-150400.4.107.1 * python310-base-debuginfo-3.10.20-150400.4.107.1 * python310-3.10.20-150400.4.107.1 * python310-tk-3.10.20-150400.4.107.1 * python310-devel-3.10.20-150400.4.107.1 * openSUSE Leap 15.4 (x86_64) * python310-base-32bit-3.10.20-150400.4.107.1 * libpython3_10-1_0-32bit-3.10.20-150400.4.107.1 * python310-base-32bit-debuginfo-3.10.20-150400.4.107.1 * python310-32bit-3.10.20-150400.4.107.1 * libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.107.1 * python310-32bit-debuginfo-3.10.20-150400.4.107.1 * openSUSE Leap 15.4 (aarch64_ilp32) * python310-64bit-debuginfo-3.10.20-150400.4.107.1 *python310-base-64bit-debuginfo-3.10.20-150400.4.107.1 * libpython3_10-1_0-64bit-debuginfo-3.10.20-150400.4.107.1 * python310-base-64bit-3.10.20-150400.4.107.1 * libpython3_10-1_0-64bit-3.10.20-150400.4.107.1 * python310-64bit-3.10.20-150400.4.107.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python310-tk-debuginfo-3.10.20-150400.4.107.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.107.1 * python310-testsuite-3.10.20-150400.4.107.1 * python310-doc-3.10.20-150400.4.107.1 * python310-base-3.10.20-150400.4.107.1 * python310-doc-devhelp-3.10.20-150400.4.107.1 * python310-dbm-debuginfo-3.10.20-150400.4.107.1 * python310-core-debugsource-3.10.20-150400.4.107.1 * python310-debuginfo-3.10.20-150400.4.107.1 * python310-curses-3.10.20-150400.4.107.1 * python310-tools-3.10.20-150400.4.107.1 * python310-idle-3.10.20-150400.4.107.1 * libpython3_10-1_0-3.10.20-150400.4.107.1 * python310-testsuite-debuginfo-3.10.20-150400.4.107.1 * python310-debugsource-3.10.20-150400.4.107.1 * python310-base-debuginfo-3.10.20-150400.4.107.1 * python310-curses-debuginfo-3.10.20-150400.4.107.1 * python310-dbm-3.10.20-150400.4.107.1 * python310-3.10.20-150400.4.107.1 * python310-tk-3.10.20-150400.4.107.1 * python310-devel-3.10.20-150400.4.107.1 * openSUSE Leap 15.6 (x86_64) * python310-base-32bit-3.10.20-150400.4.107.1 * libpython3_10-1_0-32bit-3.10.20-150400.4.107.1 * python310-base-32bit-debuginfo-3.10.20-150400.4.107.1 * python310-32bit-3.10.20-150400.4.107.1 * libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.107.1 * python310-32bit-debuginfo-3.10.20-150400.4.107.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python310-base-3.10.20-150400.4.107.1 * python310-dbm-debuginfo-3.10.20-150400.4.107.1 * python310-debugsource-3.10.20-150400.4.107.1 * python310-base-debuginfo-3.10.20-150400.4.107.1 * python310-core-debugsource-3.10.20-150400.4.107.1 * python310-curses-debuginfo-3.10.20-150400.4.107.1 * python310-dbm-3.10.20-150400.4.107.1 * python310-debuginfo-3.10.20-150400.4.107.1 * libpython3_10-1_0-3.10.20-150400.4.107.1 * python310-3.10.20-150400.4.107.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.107.1 * python310-idle-3.10.20-150400.4.107.1 * python310-tk-debuginfo-3.10.20-150400.4.107.1 * python310-tools-3.10.20-150400.4.107.1 * python310-tk-3.10.20-150400.4.107.1 * python310-curses-3.10.20-150400.4.107.1 * python310-devel-3.10.20-150400.4.107.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python310-base-3.10.20-150400.4.107.1 * python310-dbm-debuginfo-3.10.20-150400.4.107.1 * python310-debugsource-3.10.20-150400.4.107.1 * python310-base-debuginfo-3.10.20-150400.4.107.1 * python310-core-debugsource-3.10.20-150400.4.107.1 * python310-curses-debuginfo-3.10.20-150400.4.107.1 * python310-dbm-3.10.20-150400.4.107.1 * python310-debuginfo-3.10.20-150400.4.107.1 * libpython3_10-1_0-3.10.20-150400.4.107.1 * python310-3.10.20-150400.4.107.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.107.1 * python310-idle-3.10.20-150400.4.107.1 * python310-tk-debuginfo-3.10.20-150400.4.107.1 * python310-tools-3.10.20-150400.4.107.1 * python310-tk-3.10.20-150400.4.107.1 * python310-curses-3.10.20-150400.4.107.1 * python310-devel-3.10.20-150400.4.107.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python310-base-3.10.20-150400.4.107.1 * python310-dbm-debuginfo-3.10.20-150400.4.107.1 * python310-debugsource-3.10.20-150400.4.107.1 * python310-base-debuginfo-3.10.20-150400.4.107.1 * python310-core-debugsource-3.10.20-150400.4.107.1 * python310-curses-debuginfo-3.10.20-150400.4.107.1 * python310-dbm-3.10.20-150400.4.107.1 * python310-debuginfo-3.10.20-150400.4.107.1 * libpython3_10-1_0-3.10.20-150400.4.107.1 * python310-3.10.20-150400.4.107.1 *libpython3_10-1_0-debuginfo-3.10.20-150400.4.107.1 * python310-idle-3.10.20-150400.4.107.1 * python310-tk-debuginfo-3.10.20-150400.4.107.1 * python310-tools-3.10.20-150400.4.107.1 * python310-tk-3.10.20-150400.4.107.1 * python310-curses-3.10.20-150400.4.107.1 * python310-devel-3.10.20-150400.4.107.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python310-base-3.10.20-150400.4.107.1 * python310-dbm-debuginfo-3.10.20-150400.4.107.1 * python310-debugsource-3.10.20-150400.4.107.1 * python310-base-debuginfo-3.10.20-150400.4.107.1 * python310-core-debugsource-3.10.20-150400.4.107.1 * python310-curses-debuginfo-3.10.20-150400.4.107.1 * python310-dbm-3.10.20-150400.4.107.1 * python310-debuginfo-3.10.20-150400.4.107.1 * libpython3_10-1_0-3.10.20-150400.4.107.1 * python310-3.10.20-150400.4.107.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.107.1 * python310-idle-3.10.20-150400.4.107.1 * python310-tk-debuginfo-3.10.20-150400.4.107.1 * python310-tools-3.10.20-150400.4.107.1 * python310-tk-3.10.20-150400.4.107.1 * python310-curses-3.10.20-150400.4.107.1 * python310-devel-3.10.20-150400.4.107.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13462.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-3644.html * https://www.suse.com/security/cve/CVE-2026-4224.html * https://www.suse.com/security/cve/CVE-2026-4519.html * https://bugzilla.suse.com/show_bug.cgi?id=1259611 * https://bugzilla.suse.com/show_bug.cgi?id=1259734 * https://bugzilla.suse.com/show_bug.cgi?id=1259735 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1260026 . Install important updates for python310 on SUSE to address five vulnerabilities including web browser command line injection.. python310 security update. . Severity: Important. LinuxSecurity.com Team
An update that solves nine vulnerabilities can now be installed.. # Security update for python310 Announcement ID: SUSE-SU-2026:1062-1 Release Date: 2026-03-26T10:36:41Z Rating: important References: * bsc#1252974 * bsc#1254400 * bsc#1254401 * bsc#1254997 * bsc#1257029 * bsc#1257031 * bsc#1257042 * bsc#1257181 * bsc#1259240 Cross-References: * CVE-2025-11468 * CVE-2025-12084 * CVE-2025-13836 * CVE-2025-13837 * CVE-2025-6075 * CVE-2026-0672 * CVE-2026-0865 * CVE-2026-1299 * CVE-2026-2297 CVSS scores: * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-12084 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X *CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-13837 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13837 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-13837 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13837 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-6075 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-6075 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-6075 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-6075 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-1299 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1299 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-1299 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-2297 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-2297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-2297 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves nine vulnerabilities can now be installed. ## Description: This update for python310 fixes the following issues: Update to Python 3.10.20: * CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). * CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). * CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). * CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). * CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). * CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). * CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields, values, and parameters (bsc#1257042). * CVE-2026-1299: header injection whenan email is serialized due to improper newline quoting (bsc#1257181). * CVE-2026-2297: validation bypass via incorrectly handled hook in FileLoader (bsc#1259240). Changelog: * Update to 3.10.20: * gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650) (bsc#1257181, CVE-2026-1299). * gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs (bsc#1257029 CVE-2025-11468). * gh-143925: Reject control characters in data: URL media types. * gh-143919: Reject control characters in http.cookies.Morsel fields and values (bsc#1257031, CVE-2026-0672). * gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters (bsc#1257042, CVE-2026-0865). * gh-142145: Remove quadratic behavior in xml.minidom node ID cache clearing. In order to do this without breaking existing users, we also add the ownerDocument attribute to xml.dom.minidom elements and attributes created by directly instantiating the Element or Attr class. Note that this way of creating nodes is not supported; creator functions like xml.dom.Document.documentElement() should be used instead (bsc#1254997, CVE-2025-12084). * gh-137836: Add support of the "plaintext" element, RAWTEXT elements "xmp", "iframe", "noembed" and "noframes", and optionally RAWTEXT element "noscript" in html.parser.HTMLParser. * gh-136063: email.message: ensure linear complexity for legacy HTTP parameters parsing. Patch by Bndikt Tran. *gh-136065: Fix quadratic complexity in os.path.expandvars() (bsc#1252974, CVE-2025-6075). * gh-119451: Fix a potential memory denial of service in the http.client module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes (CVE-2025-13836, bsc#1254400). * gh-119452: Fix a potential memory denial of service in the http.server module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes. * gh-119342: Fix a potential memory denial of service in the plistlib module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a MemoryError, swapping, out of memory (OOM) killed processes or containers, or even system crashes (bsc#1254401, CVE-2025-13837). * Library * gh-144833: Fixed a use-after-free in ssl when SSL_new() returns NULL in newPySSLSocket(). The error was reported via a dangling pointer after the object had already been freed. * gh-144363: Update bundled libexpat to 2.7.4 * gh-90949: Add SetAllocTrackerActivationThreshold() and SetAllocTrackerMaximumAmplification() to xmlparser objects to prevent use of disproportional amounts of dynamic memory from within an Expat parser. Patch by Bndikt Tran. * Core and Builtins * gh-120384: Fix an array out of bounds crash in list_ass_subscript, which could be invoked via some specificly tailored input: including concurrent modification of a list object, where one thread assigns a slice and another clears it. * gh-120298: Fix use-after free in list_richcompare_implwhich can be invoked via some specificly tailored evil input. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1062=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1062=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-1062=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1062=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1062=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1062=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python310-core-debugsource-3.10.20-150400.4.102.1 * python310-curses-debuginfo-3.10.20-150400.4.102.1 * python310-base-debuginfo-3.10.20-150400.4.102.1 * python310-3.10.20-150400.4.102.1 * python310-tools-3.10.20-150400.4.102.1 * python310-dbm-3.10.20-150400.4.102.1 * python310-idle-3.10.20-150400.4.102.1 * python310-debuginfo-3.10.20-150400.4.102.1 * python310-devel-3.10.20-150400.4.102.1 * python310-tk-debuginfo-3.10.20-150400.4.102.1 * python310-debugsource-3.10.20-150400.4.102.1 * python310-base-3.10.20-150400.4.102.1 * libpython3_10-1_0-3.10.20-150400.4.102.1 * python310-tk-3.10.20-150400.4.102.1 * python310-curses-3.10.20-150400.4.102.1 * python310-dbm-debuginfo-3.10.20-150400.4.102.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.102.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python310-devel-3.10.20-150400.4.102.1 * libpython3_10-1_0-3.10.20-150400.4.102.1 *python310-curses-3.10.20-150400.4.102.1 * python310-curses-debuginfo-3.10.20-150400.4.102.1 * python310-testsuite-3.10.20-150400.4.102.1 * python310-doc-devhelp-3.10.20-150400.4.102.1 * python310-3.10.20-150400.4.102.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.102.1 * python310-core-debugsource-3.10.20-150400.4.102.1 * python310-base-debuginfo-3.10.20-150400.4.102.1 * python310-dbm-3.10.20-150400.4.102.1 * python310-idle-3.10.20-150400.4.102.1 * python310-debugsource-3.10.20-150400.4.102.1 * python310-base-3.10.20-150400.4.102.1 * python310-tk-3.10.20-150400.4.102.1 * python310-testsuite-debuginfo-3.10.20-150400.4.102.1 * python310-doc-3.10.20-150400.4.102.1 * python310-debuginfo-3.10.20-150400.4.102.1 * python310-tk-debuginfo-3.10.20-150400.4.102.1 * python310-tools-3.10.20-150400.4.102.1 * python310-dbm-debuginfo-3.10.20-150400.4.102.1 * openSUSE Leap 15.4 (x86_64) * python310-base-32bit-debuginfo-3.10.20-150400.4.102.1 * python310-32bit-3.10.20-150400.4.102.1 * libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.102.1 * libpython3_10-1_0-32bit-3.10.20-150400.4.102.1 * python310-32bit-debuginfo-3.10.20-150400.4.102.1 * python310-base-32bit-3.10.20-150400.4.102.1 * openSUSE Leap 15.4 (aarch64_ilp32) * python310-base-64bit-debuginfo-3.10.20-150400.4.102.1 * python310-64bit-3.10.20-150400.4.102.1 * python310-base-64bit-3.10.20-150400.4.102.1 * libpython3_10-1_0-64bit-debuginfo-3.10.20-150400.4.102.1 * python310-64bit-debuginfo-3.10.20-150400.4.102.1 * libpython3_10-1_0-64bit-3.10.20-150400.4.102.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python310-devel-3.10.20-150400.4.102.1 * libpython3_10-1_0-3.10.20-150400.4.102.1 * python310-curses-3.10.20-150400.4.102.1 * python310-curses-debuginfo-3.10.20-150400.4.102.1 * python310-testsuite-3.10.20-150400.4.102.1 * python310-doc-devhelp-3.10.20-150400.4.102.1 * python310-3.10.20-150400.4.102.1 *libpython3_10-1_0-debuginfo-3.10.20-150400.4.102.1 * python310-core-debugsource-3.10.20-150400.4.102.1 * python310-base-debuginfo-3.10.20-150400.4.102.1 * python310-dbm-3.10.20-150400.4.102.1 * python310-idle-3.10.20-150400.4.102.1 * python310-debugsource-3.10.20-150400.4.102.1 * python310-base-3.10.20-150400.4.102.1 * python310-tk-3.10.20-150400.4.102.1 * python310-testsuite-debuginfo-3.10.20-150400.4.102.1 * python310-doc-3.10.20-150400.4.102.1 * python310-debuginfo-3.10.20-150400.4.102.1 * python310-tk-debuginfo-3.10.20-150400.4.102.1 * python310-tools-3.10.20-150400.4.102.1 * python310-dbm-debuginfo-3.10.20-150400.4.102.1 * openSUSE Leap 15.6 (x86_64) * python310-base-32bit-debuginfo-3.10.20-150400.4.102.1 * python310-32bit-3.10.20-150400.4.102.1 * libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.102.1 * libpython3_10-1_0-32bit-3.10.20-150400.4.102.1 * python310-32bit-debuginfo-3.10.20-150400.4.102.1 * python310-base-32bit-3.10.20-150400.4.102.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python310-core-debugsource-3.10.20-150400.4.102.1 * python310-curses-debuginfo-3.10.20-150400.4.102.1 * python310-base-debuginfo-3.10.20-150400.4.102.1 * python310-3.10.20-150400.4.102.1 * python310-tools-3.10.20-150400.4.102.1 * python310-dbm-3.10.20-150400.4.102.1 * python310-idle-3.10.20-150400.4.102.1 * python310-debuginfo-3.10.20-150400.4.102.1 * python310-devel-3.10.20-150400.4.102.1 * python310-tk-debuginfo-3.10.20-150400.4.102.1 * python310-debugsource-3.10.20-150400.4.102.1 * python310-base-3.10.20-150400.4.102.1 * libpython3_10-1_0-3.10.20-150400.4.102.1 * python310-tk-3.10.20-150400.4.102.1 * python310-curses-3.10.20-150400.4.102.1 * python310-dbm-debuginfo-3.10.20-150400.4.102.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.102.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) *python310-core-debugsource-3.10.20-150400.4.102.1 * python310-curses-debuginfo-3.10.20-150400.4.102.1 * python310-base-debuginfo-3.10.20-150400.4.102.1 * python310-3.10.20-150400.4.102.1 * python310-tools-3.10.20-150400.4.102.1 * python310-dbm-3.10.20-150400.4.102.1 * python310-idle-3.10.20-150400.4.102.1 * python310-debuginfo-3.10.20-150400.4.102.1 * python310-devel-3.10.20-150400.4.102.1 * python310-tk-debuginfo-3.10.20-150400.4.102.1 * python310-debugsource-3.10.20-150400.4.102.1 * python310-base-3.10.20-150400.4.102.1 * libpython3_10-1_0-3.10.20-150400.4.102.1 * python310-tk-3.10.20-150400.4.102.1 * python310-curses-3.10.20-150400.4.102.1 * python310-dbm-debuginfo-3.10.20-150400.4.102.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.102.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python310-core-debugsource-3.10.20-150400.4.102.1 * python310-curses-debuginfo-3.10.20-150400.4.102.1 * python310-base-debuginfo-3.10.20-150400.4.102.1 * python310-3.10.20-150400.4.102.1 * python310-tools-3.10.20-150400.4.102.1 * python310-dbm-3.10.20-150400.4.102.1 * python310-idle-3.10.20-150400.4.102.1 * python310-debuginfo-3.10.20-150400.4.102.1 * python310-devel-3.10.20-150400.4.102.1 * python310-tk-debuginfo-3.10.20-150400.4.102.1 * python310-debugsource-3.10.20-150400.4.102.1 * python310-base-3.10.20-150400.4.102.1 * libpython3_10-1_0-3.10.20-150400.4.102.1 * python310-tk-3.10.20-150400.4.102.1 * python310-curses-3.10.20-150400.4.102.1 * python310-dbm-debuginfo-3.10.20-150400.4.102.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.102.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-12084.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-13837.html * https://www.suse.com/security/cve/CVE-2025-6075.html *https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://www.suse.com/security/cve/CVE-2026-1299.html * https://www.suse.com/security/cve/CVE-2026-2297.html * https://bugzilla.suse.com/show_bug.cgi?id=1252974 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1254401 * https://bugzilla.suse.com/show_bug.cgi?id=1254997 * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257181 * https://bugzilla.suse.com/show_bug.cgi?id=1259240 . Update for python310 addresses nine important security issues, enhancing system integrity and stability.. SUSE python310 update security vulnerabilities important. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities can now be installed.. # python310-3.10.20-2.1 on GA media Announcement ID: openSUSE-SU-2026:10404-1 Rating: moderate Cross-References: * CVE-2026-1299 * CVE-2026-2297 CVSS scores: * CVE-2026-1299 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-1299 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-2297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-2297 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the python310-3.10.20-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python310 3.10.20-2.1 * python310-curses 3.10.20-2.1 * python310-dbm 3.10.20-2.1 * python310-idle 3.10.20-2.1 * python310-tk 3.10.20-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1299.html * https://www.suse.com/security/cve/CVE-2026-2297.html . An update for openSUSE fixes two moderate security issues in python310. Install this necessary security advisory now.. openSUSE Python Update, moderate security issues, CVE fixes. . LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for python310 Announcement ID: SUSE-SU-2026:0613-1 Release Date: 2026-02-24T15:14:57Z Rating: important References: * bsc#1257029 * bsc#1257031 * bsc#1257041 * bsc#1257042 * bsc#1257044 * bsc#1257046 Cross-References: * CVE-2025-11468 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2026-0672 * CVE-2026-0865 CVSS scores: * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15366 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15367 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X *CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves six vulnerabilities can now be installed. ## Description: This update for python310 fixes the following issues: * CVE-2025-11468: header injection when folding a long comment in an email header containing exclusively unfoldable characters (bsc#1257029). * CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel (bsc#1257031). * CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042). * CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). * CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). * CVE-2025-15367: control characters may allow the injection of additional commands(bsc#1257041). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-613=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-613=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-613=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-613=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-613=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-613=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python310-curses-3.10.19-150400.4.97.1 * python310-curses-debuginfo-3.10.19-150400.4.97.1 * python310-core-debugsource-3.10.19-150400.4.97.1 * python310-base-debuginfo-3.10.19-150400.4.97.1 * python310-debuginfo-3.10.19-150400.4.97.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.97.1 * python310-doc-3.10.19-150400.4.97.1 * libpython3_10-1_0-3.10.19-150400.4.97.1 * python310-debugsource-3.10.19-150400.4.97.1 * python310-dbm-3.10.19-150400.4.97.1 * python310-tools-3.10.19-150400.4.97.1 * python310-tk-3.10.19-150400.4.97.1 * python310-tk-debuginfo-3.10.19-150400.4.97.1 * python310-dbm-debuginfo-3.10.19-150400.4.97.1 * python310-devel-3.10.19-150400.4.97.1 * python310-idle-3.10.19-150400.4.97.1 * python310-testsuite-3.10.19-150400.4.97.1 * python310-3.10.19-150400.4.97.1 * python310-base-3.10.19-150400.4.97.1 * python310-testsuite-debuginfo-3.10.19-150400.4.97.1 * python310-doc-devhelp-3.10.19-150400.4.97.1 * openSUSE Leap 15.4 (x86_64) * python310-base-32bit-3.10.19-150400.4.97.1 * libpython3_10-1_0-32bit-3.10.19-150400.4.97.1 * python310-32bit-3.10.19-150400.4.97.1 * python310-32bit-debuginfo-3.10.19-150400.4.97.1 * python310-base-32bit-debuginfo-3.10.19-150400.4.97.1 * libpython3_10-1_0-32bit-debuginfo-3.10.19-150400.4.97.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_10-1_0-64bit-3.10.19-150400.4.97.1 * libpython3_10-1_0-64bit-debuginfo-3.10.19-150400.4.97.1 * python310-64bit-debuginfo-3.10.19-150400.4.97.1 * python310-64bit-3.10.19-150400.4.97.1 * python310-base-64bit-3.10.19-150400.4.97.1 * python310-base-64bit-debuginfo-3.10.19-150400.4.97.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python310-curses-debuginfo-3.10.19-150400.4.97.1 * python310-core-debugsource-3.10.19-150400.4.97.1 * python310-base-debuginfo-3.10.19-150400.4.97.1 * python310-debuginfo-3.10.19-150400.4.97.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.97.1 * python310-doc-3.10.19-150400.4.97.1 * libpython3_10-1_0-3.10.19-150400.4.97.1 * python310-debugsource-3.10.19-150400.4.97.1 * python310-doc-devhelp-3.10.19-150400.4.97.1 * python310-dbm-3.10.19-150400.4.97.1 * python310-tools-3.10.19-150400.4.97.1 * python310-tk-3.10.19-150400.4.97.1 * python310-tk-debuginfo-3.10.19-150400.4.97.1 * python310-dbm-debuginfo-3.10.19-150400.4.97.1 * python310-devel-3.10.19-150400.4.97.1 * python310-idle-3.10.19-150400.4.97.1 * python310-testsuite-3.10.19-150400.4.97.1 * python310-3.10.19-150400.4.97.1 * python310-base-3.10.19-150400.4.97.1 * python310-testsuite-debuginfo-3.10.19-150400.4.97.1 * python310-curses-3.10.19-150400.4.97.1 * openSUSE Leap 15.6 (x86_64) * python310-base-32bit-3.10.19-150400.4.97.1 * libpython3_10-1_0-32bit-3.10.19-150400.4.97.1 * python310-32bit-3.10.19-150400.4.97.1 * python310-32bit-debuginfo-3.10.19-150400.4.97.1 * python310-base-32bit-debuginfo-3.10.19-150400.4.97.1 * libpython3_10-1_0-32bit-debuginfo-3.10.19-150400.4.97.1 * SUSELinux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python310-base-debuginfo-3.10.19-150400.4.97.1 * python310-debuginfo-3.10.19-150400.4.97.1 * python310-idle-3.10.19-150400.4.97.1 * python310-tools-3.10.19-150400.4.97.1 * python310-3.10.19-150400.4.97.1 * python310-tk-3.10.19-150400.4.97.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.97.1 * python310-base-3.10.19-150400.4.97.1 * python310-devel-3.10.19-150400.4.97.1 * libpython3_10-1_0-3.10.19-150400.4.97.1 * python310-debugsource-3.10.19-150400.4.97.1 * python310-curses-3.10.19-150400.4.97.1 * python310-tk-debuginfo-3.10.19-150400.4.97.1 * python310-curses-debuginfo-3.10.19-150400.4.97.1 * python310-dbm-debuginfo-3.10.19-150400.4.97.1 * python310-core-debugsource-3.10.19-150400.4.97.1 * python310-dbm-3.10.19-150400.4.97.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python310-base-debuginfo-3.10.19-150400.4.97.1 * python310-debuginfo-3.10.19-150400.4.97.1 * python310-idle-3.10.19-150400.4.97.1 * python310-tools-3.10.19-150400.4.97.1 * python310-3.10.19-150400.4.97.1 * python310-tk-3.10.19-150400.4.97.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.97.1 * python310-base-3.10.19-150400.4.97.1 * python310-devel-3.10.19-150400.4.97.1 * libpython3_10-1_0-3.10.19-150400.4.97.1 * python310-debugsource-3.10.19-150400.4.97.1 * python310-curses-3.10.19-150400.4.97.1 * python310-tk-debuginfo-3.10.19-150400.4.97.1 * python310-curses-debuginfo-3.10.19-150400.4.97.1 * python310-dbm-debuginfo-3.10.19-150400.4.97.1 * python310-core-debugsource-3.10.19-150400.4.97.1 * python310-dbm-3.10.19-150400.4.97.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python310-base-debuginfo-3.10.19-150400.4.97.1 * python310-debuginfo-3.10.19-150400.4.97.1 * python310-idle-3.10.19-150400.4.97.1 * python310-tools-3.10.19-150400.4.97.1 *python310-3.10.19-150400.4.97.1 * python310-tk-3.10.19-150400.4.97.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.97.1 * python310-base-3.10.19-150400.4.97.1 * python310-devel-3.10.19-150400.4.97.1 * libpython3_10-1_0-3.10.19-150400.4.97.1 * python310-debugsource-3.10.19-150400.4.97.1 * python310-curses-3.10.19-150400.4.97.1 * python310-tk-debuginfo-3.10.19-150400.4.97.1 * python310-curses-debuginfo-3.10.19-150400.4.97.1 * python310-dbm-debuginfo-3.10.19-150400.4.97.1 * python310-core-debugsource-3.10.19-150400.4.97.1 * python310-dbm-3.10.19-150400.4.97.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python310-base-debuginfo-3.10.19-150400.4.97.1 * python310-debuginfo-3.10.19-150400.4.97.1 * python310-idle-3.10.19-150400.4.97.1 * python310-tools-3.10.19-150400.4.97.1 * python310-3.10.19-150400.4.97.1 * python310-tk-3.10.19-150400.4.97.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.97.1 * python310-base-3.10.19-150400.4.97.1 * python310-devel-3.10.19-150400.4.97.1 * libpython3_10-1_0-3.10.19-150400.4.97.1 * python310-debugsource-3.10.19-150400.4.97.1 * python310-curses-3.10.19-150400.4.97.1 * python310-tk-debuginfo-3.10.19-150400.4.97.1 * python310-curses-debuginfo-3.10.19-150400.4.97.1 * python310-dbm-debuginfo-3.10.19-150400.4.97.1 * python310-core-debugsource-3.10.19-150400.4.97.1 * python310-dbm-3.10.19-150400.4.97.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html * https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257041 *https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257044 * https://bugzilla.suse.com/show_bug.cgi?id=1257046 . Important update for python310 addresses six critical issues, boosting security on SUSE systems. Take action to protect your data.. SUSE Python Update Security Patching Injection Issues. . Severity: Important. LinuxSecurity.com Team
An update that solves 6 vulnerabilities can now be installed.. # python310-3.10.19-4.1 on GA media Announcement ID: openSUSE-SU-2026:10200-1 Rating: moderate Cross-References: * CVE-2025-11468 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2026-0672 * CVE-2026-0865 CVSS scores: * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 6 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the python310-3.10.19-4.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python310 3.10.19-4.1 * python310-32bit 3.10.19-4.1 * python310-curses 3.10.19-4.1 * python310-dbm 3.10.19-4.1 * python310-idle 3.10.19-4.1 * python310-tk 3.10.19-4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html *https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html . An openSUSE update addresses 6 vulnerabilities in python310, emphasizing vital security fixes and user protection.. openSUSE python310 vulnerabilities security update. . LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for python310 Announcement ID: SUSE-SU-2026:0130-1 Release Date: 2026-01-15T13:11:13Z Rating: moderate References: * bsc#1254400 * bsc#1254401 * bsc#1254997 Cross-References: * CVE-2025-12084 * CVE-2025-13836 * CVE-2025-13837 CVSS scores: * CVE-2025-12084 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-12084 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2025-13837 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13837 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-13837 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X AffectedProducts: * openSUSE Leap 15.4 * openSUSE Leap 15.6 An update that solves three vulnerabilities can now be installed. ## Description: This update for python310 fixes the following issues: * CVE-2025-12084: quadratic complexity when building nested elements using `xml.dom.minidom` methods that depend on `_clear_id_cache()` can lead to availability issues when building excessively nested documents (bsc#1254997). * CVE-2025-13836: use of `Content-Length` by default when reading an HTTP response with no read amount specified can lead to OOM issues and DoS when a client deals with a malicious server (bsc#1254400). * CVE-2025-13837: data read by the plistlib module according to the size specified by the file itself can lead to OOM issues and DoS (bsc#1254401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-130=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-130=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python310-base-debuginfo-3.10.19-150400.4.94.1 * python310-curses-3.10.19-150400.4.94.1 * python310-debugsource-3.10.19-150400.4.94.1 * python310-base-3.10.19-150400.4.94.1 * python310-testsuite-3.10.19-150400.4.94.1 * python310-tk-debuginfo-3.10.19-150400.4.94.1 * python310-doc-devhelp-3.10.19-150400.4.94.1 * python310-curses-debuginfo-3.10.19-150400.4.94.1 * python310-testsuite-debuginfo-3.10.19-150400.4.94.1 * python310-3.10.19-150400.4.94.1 * python310-doc-3.10.19-150400.4.94.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.94.1 * python310-dbm-debuginfo-3.10.19-150400.4.94.1 * python310-tk-3.10.19-150400.4.94.1 * python310-idle-3.10.19-150400.4.94.1 * python310-devel-3.10.19-150400.4.94.1 *python310-core-debugsource-3.10.19-150400.4.94.1 * python310-dbm-3.10.19-150400.4.94.1 * python310-tools-3.10.19-150400.4.94.1 * libpython3_10-1_0-3.10.19-150400.4.94.1 * python310-debuginfo-3.10.19-150400.4.94.1 * openSUSE Leap 15.4 (x86_64) * python310-32bit-3.10.19-150400.4.94.1 * python310-base-32bit-debuginfo-3.10.19-150400.4.94.1 * python310-base-32bit-3.10.19-150400.4.94.1 * libpython3_10-1_0-32bit-3.10.19-150400.4.94.1 * python310-32bit-debuginfo-3.10.19-150400.4.94.1 * libpython3_10-1_0-32bit-debuginfo-3.10.19-150400.4.94.1 * openSUSE Leap 15.4 (aarch64_ilp32) * python310-64bit-3.10.19-150400.4.94.1 * python310-64bit-debuginfo-3.10.19-150400.4.94.1 * python310-base-64bit-3.10.19-150400.4.94.1 * libpython3_10-1_0-64bit-debuginfo-3.10.19-150400.4.94.1 * python310-base-64bit-debuginfo-3.10.19-150400.4.94.1 * libpython3_10-1_0-64bit-3.10.19-150400.4.94.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python310-base-debuginfo-3.10.19-150400.4.94.1 * python310-curses-3.10.19-150400.4.94.1 * python310-debugsource-3.10.19-150400.4.94.1 * python310-base-3.10.19-150400.4.94.1 * python310-testsuite-3.10.19-150400.4.94.1 * python310-tk-debuginfo-3.10.19-150400.4.94.1 * python310-doc-devhelp-3.10.19-150400.4.94.1 * python310-curses-debuginfo-3.10.19-150400.4.94.1 * python310-testsuite-debuginfo-3.10.19-150400.4.94.1 * python310-3.10.19-150400.4.94.1 * python310-doc-3.10.19-150400.4.94.1 * libpython3_10-1_0-debuginfo-3.10.19-150400.4.94.1 * python310-dbm-debuginfo-3.10.19-150400.4.94.1 * python310-tk-3.10.19-150400.4.94.1 * python310-idle-3.10.19-150400.4.94.1 * python310-devel-3.10.19-150400.4.94.1 * python310-core-debugsource-3.10.19-150400.4.94.1 * python310-dbm-3.10.19-150400.4.94.1 * python310-tools-3.10.19-150400.4.94.1 * libpython3_10-1_0-3.10.19-150400.4.94.1 * python310-debuginfo-3.10.19-150400.4.94.1 * openSUSE Leap 15.6 (x86_64) *python310-32bit-3.10.19-150400.4.94.1 * python310-base-32bit-debuginfo-3.10.19-150400.4.94.1 * python310-base-32bit-3.10.19-150400.4.94.1 * libpython3_10-1_0-32bit-3.10.19-150400.4.94.1 * python310-32bit-debuginfo-3.10.19-150400.4.94.1 * libpython3_10-1_0-32bit-debuginfo-3.10.19-150400.4.94.1 ## References: * https://www.suse.com/security/cve/CVE-2025-12084.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-13837.html * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1254401 * https://bugzilla.suse.com/show_bug.cgi?id=1254997 . This update addresses three moderate issues in python310, including DoS risks and memory consumption.. python310 update, SUSE security, openSUSE vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.