Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3132-1

Опубликовано: 20 июл. 2026
Источник: suse-cvrf

Описание

Security update for python311

This update for python311 fixes the following issues

  • CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969).
  • CVE-2026-4786: URLs containing %action can bypass mitigation that allows command injection via the webbrowser.open() API (bsc#1262319).
  • CVE-2026-6019: HTML parser-sensitive sequence not neutralized by http.cookies.Morsel.js_output() (bsc#1262654).
  • CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a MemoryError and the decompression instance is re-used (bsc#1262098).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1
SUSE Linux Enterprise Module for Public Cloud 15 SP4
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
SUSE Linux Enterprise Server 15 SP4-LTSS
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1
SUSE Linux Enterprise Server 15 SP5-LTSS
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
libpython3_11-1_0-3.11.15-150400.9.91.1
python311-3.11.15-150400.9.91.1
python311-base-3.11.15-150400.9.91.1
python311-curses-3.11.15-150400.9.91.1
python311-dbm-3.11.15-150400.9.91.1
python311-devel-3.11.15-150400.9.91.1
python311-doc-3.11.15-150400.9.91.1
python311-doc-devhelp-3.11.15-150400.9.91.1
python311-idle-3.11.15-150400.9.91.1
python311-tk-3.11.15-150400.9.91.1
python311-tools-3.11.15-150400.9.91.1

Описание

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpython3_11-1_0-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-base-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-curses-3.11.15-150400.9.91.1

Ссылки

Описание

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpython3_11-1_0-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-base-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-curses-3.11.15-150400.9.91.1

Ссылки

Описание

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpython3_11-1_0-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-base-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-curses-3.11.15-150400.9.91.1

Ссылки

Описание

Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpython3_11-1_0-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-base-3.11.15-150400.9.91.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-curses-3.11.15-150400.9.91.1

Ссылки