Описание
Security update for python-tornado6
This update for python-tornado6 fixes the following issues:
- CVE-2026-31958: parsing large multipart bodies with many parts can cause a denial of service (bsc#1259553).
- incomplete validation of cookie attributes allows for injection of user-controlled values in other cookie attributes (bsc#1259630).
Список пакетов
Container suse/multi-linux-manager/5.1/x86_64/proxy-salt-broker:latest
python311-tornado6-6.3.2-150400.9.15.1
Container suse/multi-linux-manager/5.1/x86_64/server-saline:latest
python311-tornado6-6.3.2-150400.9.15.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-BYOS-Azure
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-BYOS-EC2
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-BYOS-GCE
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-HPC-BYOS-Azure
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-HPC-BYOS-EC2
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-HPC-BYOS-GCE
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-Hardened-BYOS-Azure
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-Hardened-BYOS-EC2
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-Hardened-BYOS-GCE
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-SAP-BYOS-Azure
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-SAP-BYOS-EC2
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-SAP-BYOS-GCE
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
python311-tornado6-6.3.2-150400.9.15.1
Image proxy-salt-broker-image
python311-tornado6-6.3.2-150400.9.15.1
Image server-image-sles15sp7
python311-tornado6-6.3.2-150400.9.15.1
Image server-saline-image
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise Module for Python 3 15 SP7
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise Server 15 SP4-LTSS
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise Server 15 SP5-LTSS
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise Server 15 SP6-LTSS
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
python311-tornado6-6.3.2-150400.9.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
python311-tornado6-6.3.2-150400.9.15.1
openSUSE Leap 15.6
python311-tornado6-6.3.2-150400.9.15.1
Ссылки
- Link for SUSE-SU-2026:1064-1
- E-Mail link for SUSE-SU-2026:1064-1
- SUSE Security Ratings
- SUSE Bug 1259553
- SUSE Bug 1259630
- SUSE CVE CVE-2026-31958 page
Описание
Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.
Затронутые продукты
Container suse/multi-linux-manager/5.1/x86_64/proxy-salt-broker:latest:python311-tornado6-6.3.2-150400.9.15.1
Container suse/multi-linux-manager/5.1/x86_64/server-saline:latest:python311-tornado6-6.3.2-150400.9.15.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest:python311-tornado6-6.3.2-150400.9.15.1
Image SLES15-SP7-BYOS-Azure:python311-tornado6-6.3.2-150400.9.15.1
Ссылки
- CVE-2026-31958
- SUSE Bug 1259552