FlawAtlas
Search the atlas
SUSE-SU-2025:02050-1 Not scored

Security update for python39

This update for python39 fixes the following issues: python39 was updated from version 3.9.21 to version 3.9.23: - Security issues fixed: * CVE-2025-4516: Fixed blocking DecodeError handling vulnerability, which could lead to DoS (bsc#1243273) * CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4517: Fixed multiple issues that allowed tarfile extraction filters to be bypassed using crafted symlinks and hard links (bsc#1244056, bsc#1244059, bsc#1244060, bsc#1244032) - Other changes and bugs fixed: * Fixed issue with reproducible builds (bsc#1239210) * Fixed a potential denial of service vulnerability in the imaplib module. * Fixed bugs in the in the folding of rfc2047 encoded-words and in the folding of quoted strings when flattening an email message using a modern email policy. * Fixed parsing long IPv6 addresses with embedded IPv4 address. * Fixed ipaddress.IPv6Address.reverse_pointer output according to RFC 3596, §2.5. * Improved the textual representation of IPv4-mapped IPv6 addresses in ipaddress. * ipaddress: fixed hash collisions for IPv4Network and IPv6Network objects * os.path.realpath() now accepts a strict keyword-only argument. * Stop the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. * Updated bundled libexpat to 2.7.1 * Writers of CPython’s documentation can now use next as the version for the versionchanged, versionadded, deprecated directives.

Exploit probability Not scored
Published June 20, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 python39
SUSE:Enterprise Storage 7.1 python39-core
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python39
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS python39-core
SUSE:Linux Enterprise Server 15 SP3-LTSS python39
SUSE:Linux Enterprise Server 15 SP3-LTSS python39-core
SUSE:Linux Enterprise Server 15 SP5-LTSS python39
SUSE:Linux Enterprise Server 15 SP5-LTSS python39-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python39
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 python39-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 python39
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 python39-core
openSUSE:Leap 15.6 python39
openSUSE:Leap 15.6 python39-core
openSUSE:Leap 15.6 python39-documentation

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:02050-1

This update for python39 fixes the following issues: python39 was updated from version 3.9.21 to version 3.9.23: - Security issues fixed: * CVE-2025-4516: Fixed blocking DecodeError handling vulnerability, which could lead to DoS (bsc#1243273) * CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4517: Fixed multiple issues that allowed tarfile extraction filters to be bypassed using crafted symlinks and hard links (bsc#1244056, bsc#1244059, bsc#1244060, bsc#1244032) - Other changes and bugs fixed: * Fixed issue with reproducible builds (bsc#1239210) * Fixed a potential denial of service vulnerability in the imaplib module. * Fixed bugs in the in the folding of rfc2047 encoded-words and in the folding of quoted strings when flattening an email message using a modern email policy. * Fixed parsing long IPv6 addresses with embedded IPv4 address. * Fixed ipaddress.IPv6Address.reverse_pointer output according to RFC 3596, §2.5. * Improved the textual representation of IPv4-mapped IPv6 addresses in ipaddress. * ipaddress: fixed hash collisions for IPv4Network and IPv6Network objects * os.path.realpath() now accepts a strict keyword-only argument. * Stop the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. * Updated bundled libexpat to 2.7.1 * Writers of CPython’s documentation can now use next as the version for the versionchanged, versionadded, deprecated directives.

View original source

05 / REFERENCES

Further evidence