Описание
Security update for python39
This update for python39 fixes the following issue:
- CVE-2026-2297: validation bypass via incorrectly handled hook in FileLoader (bsc#1259240).
Список пакетов
openSUSE Leap 15.6
libpython3_9-1_0-3.9.25-150300.4.96.1
libpython3_9-1_0-32bit-3.9.25-150300.4.96.1
python39-3.9.25-150300.4.96.1
python39-32bit-3.9.25-150300.4.96.1
python39-base-3.9.25-150300.4.96.1
python39-base-32bit-3.9.25-150300.4.96.1
python39-curses-3.9.25-150300.4.96.1
python39-dbm-3.9.25-150300.4.96.1
python39-devel-3.9.25-150300.4.96.1
python39-doc-3.9.25-150300.4.96.1
python39-doc-devhelp-3.9.25-150300.4.96.1
python39-idle-3.9.25-150300.4.96.1
python39-testsuite-3.9.25-150300.4.96.1
python39-tk-3.9.25-150300.4.96.1
python39-tools-3.9.25-150300.4.96.1
Ссылки
- Link for SUSE-SU-2026:0971-1
- E-Mail link for SUSE-SU-2026:0971-1
- SUSE Security Ratings
- SUSE Bug 1259240
- SUSE CVE CVE-2026-2297 page
Описание
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.
Затронутые продукты
openSUSE Leap 15.6:libpython3_9-1_0-3.9.25-150300.4.96.1
openSUSE Leap 15.6:libpython3_9-1_0-32bit-3.9.25-150300.4.96.1
openSUSE Leap 15.6:python39-3.9.25-150300.4.96.1
openSUSE Leap 15.6:python39-32bit-3.9.25-150300.4.96.1
Ссылки
- CVE-2026-2297
- SUSE Bug 1259240