{"id":"SUSE-SU-2026:3855-1","summary":"Security update for python36","details":"This update for python36 fixes the following issues:\n\n- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the\n  `configparser` module is used (bsc#1269066).\n- CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF bytes (bsc#1261969).\n- CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously\n  crafted `wheel` archives (bsc#1257599).\n- CVE-2026-3219: `pip` handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is\n  both a tar and ZIP file (bsc#1262467).\n- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted\n  Unicode input (bsc#1267581).  \n- CVE-2026-4360: in the `Tarfile.extract()` function, the filter parameter is not passed properly when extracting\n  hardlinks (bsc#1269959).\n- CVE-2026-4786: URLs prefixed with `%action` can pass the dash-prefix safety check and allow for command injection\n  (bsc#1262319).\n- CVE-2026-6019: `BaseCookie.js_output()` does not neutralize characters in cookie values embedded in JS (bsc#1262654).\n- CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with `MemoryError` and the\n  decompression instance is re-used (bsc#1262098).\n- CVE-2026-6357: `pip` `self-update` functionality can import newly installed modules after wheel installation \n  (bsc#1263442, bsc#1263443).\n- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding\n  protection (bsc#1264962).\n- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory\n  (bsc#1267821).\n- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).\n- CVE-2026-8643: path traversal via malicious entry point name in `pip` `wheel` installation allows arbitrary file\n  overwrite (bsc#1266669).\n- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and\n  enables arbitrary file reads and writes (bsc#1268977).\n- CVE-2026-11972: infinite loop due to improper EOF handling in the `tarfile` module streaming mode can lead to DoS\n  (bsc#1269788).\n- CVE-2026-15308: incremental `HTMLParser` allows CPU-exhaustion DoS via repeated unterminated markup declarations\n  (bsc#1271192).\n- Regression in `http.cookies` due to CVE-2026-6019 fix not handling non-ASCII characters correctly (bsc#1263083).\n","modified":"2026-09-04T18:23:40.583463384Z","published":"2026-08-28T12:15:45Z","related":["CVE-2026-0864","CVE-2026-11940","CVE-2026-11972","CVE-2026-1502","CVE-2026-15308","CVE-2026-1703","CVE-2026-3219","CVE-2026-3276","CVE-2026-4360","CVE-2026-4786","CVE-2026-6019","CVE-2026-6100","CVE-2026-6357","CVE-2026-7210","CVE-2026-7774","CVE-2026-8328","CVE-2026-8643"],"upstream":["CVE-2026-0864","CVE-2026-11940","CVE-2026-11972","CVE-2026-1502","CVE-2026-15308","CVE-2026-1703","CVE-2026-3219","CVE-2026-3276","CVE-2026-4360","CVE-2026-4786","CVE-2026-6019","CVE-2026-6100","CVE-2026-6357","CVE-2026-7210","CVE-2026-7774","CVE-2026-8328","CVE-2026-8643"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263855-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257599"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261969"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262098"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262467"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262654"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263083"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263442"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263443"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264962"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265268"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266669"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267581"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268977"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269066"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269959"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271192"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6100"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7210"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8643"}],"affected":[{"package":{"name":"python36","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-116.1"}]}],"ecosystem_specific":{"binaries":[{"python36-base":"3.6.15-116.1","python36-devel":"3.6.15-116.1","libpython3_6m1_0":"3.6.15-116.1","libpython3_6m1_0-32bit":"3.6.15-116.1","python36":"3.6.15-116.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3855-1.json"}},{"package":{"name":"python36-core","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-116.1"}]}],"ecosystem_specific":{"binaries":[{"libpython3_6m1_0":"3.6.15-116.1","libpython3_6m1_0-32bit":"3.6.15-116.1","python36":"3.6.15-116.1","python36-base":"3.6.15-116.1","python36-devel":"3.6.15-116.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3855-1.json"}},{"package":{"name":"python36","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-116.1"}]}],"ecosystem_specific":{"binaries":[{"python36-base":"3.6.15-116.1","python36-devel":"3.6.15-116.1","libpython3_6m1_0":"3.6.15-116.1","libpython3_6m1_0-32bit":"3.6.15-116.1","python36":"3.6.15-116.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3855-1.json"}},{"package":{"name":"python36-core","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-116.1"}]}],"ecosystem_specific":{"binaries":[{"python36":"3.6.15-116.1","python36-base":"3.6.15-116.1","python36-devel":"3.6.15-116.1","libpython3_6m1_0":"3.6.15-116.1","libpython3_6m1_0-32bit":"3.6.15-116.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3855-1.json"}}],"schema_version":"1.9.0"}