{"id":"SUSE-SU-2026:4401-1","summary":"Security update for python313","details":"This update for python313 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2026-6879: quadratic behavior in `xml.etree.ElementPath` index predicates can lead to a denial of service via high\n  CPU usage (bsc#1273148).\n- CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974).\n- CVE-2026-17084: [Security-announce][] StringPrep algorithm considered (bsc#1276226).\n- CVE-2026-18503: attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect\n  sniffing and consume significant CPU (bsc#1274683).\n\nNon security issue fixed:\n\n- Conflicts between different versions of Python (bsc#1258364).\n- Updated to version 3.13.15\n","modified":"2026-10-01T11:15:05.095202212Z","published":"2026-09-30T08:56:07Z","related":["CVE-2026-17084","CVE-2026-18503","CVE-2026-6879","CVE-2026-9669"],"upstream":["CVE-2026-17084","CVE-2026-18503","CVE-2026-6879","CVE-2026-9669"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264401-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258364"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267974"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273099"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273148"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274683"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276226"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-17084"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9669"}],"affected":[{"package":{"name":"python313","ecosystem":"SUSE:Linux Enterprise Module for Python 3 15 SP7","purl":"pkg:rpm/suse/python313&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.15-150700.4.56.1"}]}],"ecosystem_specific":{"binaries":[{"python313-dbm":"3.13.15-150700.4.56.1","python313":"3.13.15-150700.4.56.1","python313-tk":"3.13.15-150700.4.56.1","python313-base":"3.13.15-150700.4.56.1","libpython3_13-1_0":"3.13.15-150700.4.56.1","python313-curses":"3.13.15-150700.4.56.1","python313-tools":"3.13.15-150700.4.56.1","python313-devel":"3.13.15-150700.4.56.1","python313-idle":"3.13.15-150700.4.56.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4401-1.json"}},{"package":{"name":"python313-core","ecosystem":"SUSE:Linux Enterprise Module for Python 3 15 SP7","purl":"pkg:rpm/suse/python313-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.15-150700.4.56.1"}]}],"ecosystem_specific":{"binaries":[{"libpython3_13-1_0":"3.13.15-150700.4.56.1","python313-idle":"3.13.15-150700.4.56.1","python313-curses":"3.13.15-150700.4.56.1","python313-dbm":"3.13.15-150700.4.56.1","python313-tools":"3.13.15-150700.4.56.1","python313":"3.13.15-150700.4.56.1","python313-base":"3.13.15-150700.4.56.1","python313-devel":"3.13.15-150700.4.56.1","python313-tk":"3.13.15-150700.4.56.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4401-1.json"}}],"schema_version":"1.9.0"}