Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1365-1

Опубликовано: 15 апр. 2026
Источник: suse-cvrf

Описание

Security update for python

This update for python fixes the following issues:

  • CVE-2026-3479: improper resource argument validation in pkgutil.get_data can allow path traversal (bsc#1259989).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP7
libpython2_7-1_0-2.7.18-150000.114.1
python-2.7.18-150000.114.1
python-base-2.7.18-150000.114.1
python-curses-2.7.18-150000.114.1
python-gdbm-2.7.18-150000.114.1
python-xml-2.7.18-150000.114.1

Описание

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:libpython2_7-1_0-2.7.18-150000.114.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python-2.7.18-150000.114.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python-base-2.7.18-150000.114.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:python-curses-2.7.18-150000.114.1

Ссылки