← Search the atlas
SUSE-SU-2025:4257-2
Not scored
Security update for python311
This update for python311 fixes the following issues:
Update to 3.11.14:
- CVE-2025-6075: Fixed simple quadratic complexity vulnerabilities of os.path.expandvars() (bsc#1252974)
- CVE-2025-8291: Fixed validity of the ZIP64 End of Central Directory (EOCD) not checked by the 'zipfile' module (bsc#1251305)
Exploit probability
Not scored
Published
December 15, 2025
Required by
Not available
Last source change
March 23, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-documentation
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-documentation
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-documentation
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-documentation
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311-core
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311-documentation
SUSE:Linux Enterprise Server 15 SP5-LTSS
python311
SUSE:Linux Enterprise Server 15 SP5-LTSS
python311-core
SUSE:Linux Enterprise Server 15 SP5-LTSS
python311-documentation
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311-documentation
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
python311
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
python311-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
python311-documentation
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2025:4257-2
This update for python311 fixes the following issues:
Update to 3.11.14:
- CVE-2025-6075: Fixed simple quadratic complexity vulnerabilities of os.path.expandvars() (bsc#1252974)
- CVE-2025-8291: Fixed validity of the ZIP64 End of Central Directory (EOCD) not checked by the 'zipfile' module (bsc#1251305)
View original source ↗
05 / REFERENCES
Further evidence