{"id":"SUSE-SU-2026:4174-1","summary":"Security update for python39.SUSE_SLE-15-SP3_Update","details":"This update for python39.SUSE_SLE-15-SP3_Update fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the\n  `configparser` module is used (bsc#1269066).\n- CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously\n  crafted wheel archives (bsc#1274743).\n- CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429).\n- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted\n  Unicode input (bsc#1267581).\n- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting\n  hardlinks (bsc#1269959).\n- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory\n  (bsc#1267821).\n- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS\n  (bsc#1269788).\n- CVE-2026-13346: Arbitrary file installation via malicious package indexes (bsc#1273090 bsc#1273091 bsc#1273094).\n- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations\n  (bsc#1271192).\n\nNon security issues fixed:\n\n- crypto-policies: Extend the crypto-policies support for mozilla-nss, openjdk, krb5, bind, stunnel, openssh, libssh and\n  more packages (bsc#1211301).\n- Update bundled pip wheels to pip-20.0.2-py2.py3-none-any.whl\n","modified":"2026-09-15T17:00:04.356714110Z","published":"2026-09-14T10:26:52Z","related":["CVE-2026-0864","CVE-2026-11972","CVE-2026-13346","CVE-2026-15308","CVE-2026-1703","CVE-2026-3219","CVE-2026-3276","CVE-2026-4360","CVE-2026-7774"],"upstream":["CVE-2026-0864","CVE-2026-11972","CVE-2026-13346","CVE-2026-15308","CVE-2026-1703","CVE-2026-3219","CVE-2026-3276","CVE-2026-4360","CVE-2026-7774"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264174-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267581"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269066"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269959"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271192"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273090"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273094"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274743"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276903"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7774"}],"affected":[{"package":{"name":"python39","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/python39&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.9.25-150300.4.109.1"}]}],"ecosystem_specific":{"binaries":[{"python39":"3.9.25-150300.4.109.1","python39-base":"3.9.25-150300.4.109.1","python39-curses":"3.9.25-150300.4.109.1","python39-dbm":"3.9.25-150300.4.109.1","libpython3_9-1_0":"3.9.25-150300.4.109.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4174-1.json"}},{"package":{"name":"python39-core","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/python39-core&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.9.25-150300.4.109.1"}]}],"ecosystem_specific":{"binaries":[{"python39-dbm":"3.9.25-150300.4.109.1","libpython3_9-1_0":"3.9.25-150300.4.109.1","python39":"3.9.25-150300.4.109.1","python39-base":"3.9.25-150300.4.109.1","python39-curses":"3.9.25-150300.4.109.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4174-1.json"}},{"package":{"name":"python39","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/python39&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.9.25-150300.4.109.1"}]}],"ecosystem_specific":{"binaries":[{"python39-curses":"3.9.25-150300.4.109.1","python39-dbm":"3.9.25-150300.4.109.1","libpython3_9-1_0":"3.9.25-150300.4.109.1","python39":"3.9.25-150300.4.109.1","python39-base":"3.9.25-150300.4.109.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4174-1.json"}},{"package":{"name":"python39-core","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/python39-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.9.25-150300.4.109.1"}]}],"ecosystem_specific":{"binaries":[{"python39-dbm":"3.9.25-150300.4.109.1","libpython3_9-1_0":"3.9.25-150300.4.109.1","python39":"3.9.25-150300.4.109.1","python39-base":"3.9.25-150300.4.109.1","python39-curses":"3.9.25-150300.4.109.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4174-1.json"}}],"schema_version":"1.9.0"}