FlawAtlas
Search the atlas
SUSE-SU-2025:02047-1 Not scored

Security update for python310

This update for python310 fixes the following issues: python310 was updated from version 3.10.16 to 3.10.18: - Security issues fixed: * CVE-2025-4516: Fixed blocking DecodeError handling vulnerability, which could lead to DoS (bsc#1243273) * CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4517: Fixed multiple issues that allowed tarfile extraction filters to be bypassed using crafted symlinks and hard links (bsc#1244056, bsc#1244059, bsc#1244060, bsc#1244032) - Other changes and bugs fixed: * Improved handling of system call failures that OpenSSL reports (bsc#1241067) * Fixed issue with test_ssl pass with OpenSSL 3.5 (bsc#1241067) * Fixed issue with reproducible builds (bsc#1239210) * Fixed a potential denial of service vulnerability in the imaplib module. * Fixed bugs in the in the folding of rfc2047 encoded-words and in the folding of quoted strings when flattening an email message using a modern email policy. * Fixed parsing long IPv6 addresses with embedded IPv4 address. * Fixed ipaddress.IPv6Address.reverse_pointer output according to RFC 3596 * Improved handling of system call failures that OpenSSL reports * Improved the textual representation of IPv4-mapped IPv6 addresses in ipaddress. * ipaddress: fixed hash collisions for IPv4Network and IPv6Network objects * os.path.realpath() now accepts a strict keyword-only argument. * Stop the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. * Updated bundled libexpat to 2.7.1 * Writers of documentation can now use next as the version for the versionchanged, versionadded, deprecated directives.

Exploit probability Not scored
Published June 20, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS python310
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS python310-core
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS python310
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS python310-core
SUSE:Linux Enterprise Server 15 SP4-LTSS python310
SUSE:Linux Enterprise Server 15 SP4-LTSS python310-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 python310
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 python310-core
openSUSE:Leap 15.6 python310
openSUSE:Leap 15.6 python310-core
openSUSE:Leap 15.6 python310-documentation

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:02047-1

This update for python310 fixes the following issues: python310 was updated from version 3.10.16 to 3.10.18: - Security issues fixed: * CVE-2025-4516: Fixed blocking DecodeError handling vulnerability, which could lead to DoS (bsc#1243273) * CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4517: Fixed multiple issues that allowed tarfile extraction filters to be bypassed using crafted symlinks and hard links (bsc#1244056, bsc#1244059, bsc#1244060, bsc#1244032) - Other changes and bugs fixed: * Improved handling of system call failures that OpenSSL reports (bsc#1241067) * Fixed issue with test_ssl pass with OpenSSL 3.5 (bsc#1241067) * Fixed issue with reproducible builds (bsc#1239210) * Fixed a potential denial of service vulnerability in the imaplib module. * Fixed bugs in the in the folding of rfc2047 encoded-words and in the folding of quoted strings when flattening an email message using a modern email policy. * Fixed parsing long IPv6 addresses with embedded IPv4 address. * Fixed ipaddress.IPv6Address.reverse_pointer output according to RFC 3596 * Improved handling of system call failures that OpenSSL reports * Improved the textual representation of IPv4-mapped IPv6 addresses in ipaddress. * ipaddress: fixed hash collisions for IPv4Network and IPv6Network objects * os.path.realpath() now accepts a strict keyword-only argument. * Stop the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. * Updated bundled libexpat to 2.7.1 * Writers of documentation can now use next as the version for the versionchanged, versionadded, deprecated directives.

View original source

05 / REFERENCES

Further evidence