← Search the atlas
SUSE-SU-2026:0299-1
Not scored
Security update for python311
This update for python311 fixes the following issues:
- CVE-2025-12084: prevent quadratic behavior in node ID cache clearing (bsc#1254997).
- CVE-2025-13836: prevent reading an HTTP response from a server, if no read amount is specified, with using Content-Length per default as the length (bsc#1254400).
- CVE-2025-13837: protect against OOM when loading malicious content (bsc#1254401).
Exploit probability
Not scored
Published
January 26, 2026
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-documentation
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-documentation
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-documentation
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-documentation
SUSE:Linux Enterprise Module for Public Cloud 15 SP4
python311
SUSE:Linux Enterprise Module for Public Cloud 15 SP4
python311-core
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311-core
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311-documentation
SUSE:Linux Enterprise Server 15 SP5-LTSS
python311
SUSE:Linux Enterprise Server 15 SP5-LTSS
python311-core
SUSE:Linux Enterprise Server 15 SP5-LTSS
python311-documentation
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311-documentation
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
python311
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
python311-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
python311-documentation
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2026:0299-1
This update for python311 fixes the following issues:
- CVE-2025-12084: prevent quadratic behavior in node ID cache clearing (bsc#1254997).
- CVE-2025-13836: prevent reading an HTTP response from a server, if no read amount is specified, with using Content-Length per default as the length (bsc#1254400).
- CVE-2025-13837: protect against OOM when loading malicious content (bsc#1254401).
View original source ↗
05 / REFERENCES
Further evidence