Описание
Security update for python
This update for python fixes the following issues:
- CVE-2026-3479: improper resource argument validation in
pkgutil.get_datacan allow path traversal (bsc#1259989).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
libpython2_7-1_0-2.7.18-150000.114.1
python-2.7.18-150000.114.1
python-base-2.7.18-150000.114.1
python-curses-2.7.18-150000.114.1
python-gdbm-2.7.18-150000.114.1
python-xml-2.7.18-150000.114.1
Ссылки
- Link for SUSE-SU-2026:1365-1
- E-Mail link for SUSE-SU-2026:1365-1
- SUSE Security Ratings
- SUSE Bug 1259989
- SUSE CVE CVE-2026-3479 page
Описание
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:libpython2_7-1_0-2.7.18-150000.114.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python-2.7.18-150000.114.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python-base-2.7.18-150000.114.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python-curses-2.7.18-150000.114.1
Ссылки
- CVE-2026-3479
- SUSE Bug 1259989