SB20260116124 - SUSE update for python 



SB20260116124 - SUSE update for python

Published: January 16, 2026

Security Bulletin ID SB20260116124
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Inefficient algorithmic complexity (CVE-ID: CVE-2025-12084)

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to usage of a quadratic algorithm when building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache(). A remote attacker can force the application to create excessively nested documents, leading to a denial of service condition. 


2) Resource exhaustion (CVE-ID: CVE-2025-13836)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when reading HTTP responses in Lib/http/client.py. A remote attacker can trigger memory exhaustion and perform a denial of service (DoS) attack.


3) Input validation error (CVE-ID: CVE-2025-8291)

The vulnerability allows a remote attacker to extract files into arbitrary locations on the system.

The vulnerability exists due to the zipfile module does not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value when extracting files. A remote attacker can use a specially crafted zip file to extract data into arbitrary locations on the system.


Remediation

Install update from vendor's website.