Security update for python311
This update for python311 fixes the following issues: Updated to Python 3.11.15: - CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). - CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). - CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). - CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). - CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). - CVE-2025-15282: control characters in URL media types data (bsc#1257046). - CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). - CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields, values, and parameters (bsc#1257042).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python311 fixes the following issues: Updated to Python 3.11.15: - CVE-2025-6075: quadratic complexity in os.path.expandvars() (bsc#1252974). - CVE-2025-11468: header injection with carefully crafted inputs (bsc#1257029). - CVE-2025-12084: quadratic complexity in xml.minidom node ID cache clearing (bsc#1254997). - CVE-2025-13836: potential memory denial of service in the http.client module (bsc#1254400). - CVE-2025-13837: potential memory denial of service in the plistlib module (bsc#1254401). - CVE-2025-15282: control characters in URL media types data (bsc#1257046). - CVE-2026-0672: control characters in http.cookies.Morsel fields and values (bsc#1257031). - CVE-2026-0865: C0 control characters within wsgiref.headers.Headers fields, values, and parameters (bsc#1257042).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1252974
- https://bugzilla.suse.com/1254400
- https://bugzilla.suse.com/1254401
- https://bugzilla.suse.com/1254997
- https://bugzilla.suse.com/1257029
- https://bugzilla.suse.com/1257031
- https://bugzilla.suse.com/1257042
- https://bugzilla.suse.com/1257046
- https://www.suse.com/security/cve/CVE-2025-11468
- https://www.suse.com/security/cve/CVE-2025-12084
- https://www.suse.com/security/cve/CVE-2025-13836
- https://www.suse.com/security/cve/CVE-2025-13837
- https://www.suse.com/security/cve/CVE-2025-15282
- https://www.suse.com/security/cve/CVE-2025-6075
- https://www.suse.com/security/cve/CVE-2026-0672
- https://www.suse.com/security/cve/CVE-2026-0865
- https://www.suse.com/support/update/announcement/2026/suse-su-202620796-1/