Описание
Security update for python39
This update for python39 fixes the following issues:
Security issues fixed:
- CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969).
- CVE-2026-3446: base64 decoding stops at first padded quad by default and ignores other information that could be processed (bsc#1261970).
- CVE-2026-3479: improper resource argument validation in
pkgutil.get_data()can lead to path traversal (bsc#1259989). - CVE-2026-4786: URLs prefixed with
%actioncan pass the dash-prefix safety check and allow for command injection (bsc#1262319). - CVE-2026-6019:
BaseCookie.js_output()does not neutralize characters in cookie values embedded in JS (bsc#1262654). - CVE-2026-6100: use-after-free in
lzma.LZMADecompressor,bz2.BZ2Decompressor, andgzip.GzipFilewhen process is under memory pressure(bsc#1262098).
Other updates and bugfixes:
- Rewrite structure of Python interpreter packages.
python3*symbols should be now provided by real python3 packages and its subpackages instead of the virtual provides (bsc#1258364).
Список пакетов
SUSE Linux Enterprise Server 15 SP5-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Ссылки
- Link for SUSE-SU-2026:1818-1
- E-Mail link for SUSE-SU-2026:1818-1
- SUSE Security Ratings
- SUSE Bug 1258364
- SUSE Bug 1259989
- SUSE Bug 1261969
- SUSE Bug 1261970
- SUSE Bug 1262098
- SUSE Bug 1262319
- SUSE Bug 1262654
- SUSE CVE CVE-2026-1502 page
- SUSE CVE CVE-2026-3446 page
- SUSE CVE CVE-2026-3479 page
- SUSE CVE CVE-2026-4786 page
- SUSE CVE CVE-2026-6019 page
- SUSE CVE CVE-2026-6100 page
Описание
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Затронутые продукты
Ссылки
- CVE-2026-1502
- SUSE Bug 1261969
Описание
When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data.
Затронутые продукты
Ссылки
- CVE-2026-3446
- SUSE Bug 1261970
Описание
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Затронутые продукты
Ссылки
- CVE-2026-3479
- SUSE Bug 1259989
Описание
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Затронутые продукты
Ссылки
- CVE-2026-4786
- SUSE Bug 1260026
- SUSE Bug 1262319
Описание
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
Затронутые продукты
Ссылки
- CVE-2026-6019
- SUSE Bug 1262654
Описание
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.
Затронутые продукты
Ссылки
- CVE-2026-6100
- SUSE Bug 1262098