FlawAtlas
Search the atlas
SUSE-SU-2026:20768-1 Not scored

Security update for python311

This update for python311 fixes the following issues: Updated to Python 3.11.15: - CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). - CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). - CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). - CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). - CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). - CVE-2025-15282: control characters in URL media types data (bsc#1257046). - CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). - CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields, values, and parameters (bsc#1257042).

Exploit probability Not scored
Published March 20, 2026
Required by Not available
Last source change March 25, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Micro 6.1 python311
SUSE:Linux Micro 6.1 python311-core

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:20768-1

This update for python311 fixes the following issues: Updated to Python 3.11.15: - CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). - CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). - CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). - CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). - CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). - CVE-2025-15282: control characters in URL media types data (bsc#1257046). - CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). - CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields, values, and parameters (bsc#1257042).

View original source

05 / REFERENCES

Further evidence