Critical Vulnerabilities in Python310 Affecting openSUSE and SUSE Systems

Critical Vulnerabilities in Python310 Affecting openSUSE and SUSE Systems

First seen 8 Aug 2026, 17:35 UTC Linuxsecurity 94% similarity 72.0

Article Content

Browse articles
ThreatCluster

A significant update for python310 has been released, addressing multiple vulnerabilities including CVE-2026-0864, which allows for configuration file injection, and CVE-2026-3276, which can lead to denial-of-service (DoS) attacks. Other vulnerabilities include issues with tarfile extraction and insufficient entropy in XML parsers. The vulnerabilities affect various SUSE Linux distributions, including SUSE Linux Enterprise Server and openSUSE Leap. Administrators are urged to apply patches using the recommended installation methods. The vulnerabilities were disclosed between May and June 2026, with the update released on August 7, 2026. The CVEs have been assigned varying CVSS scores, indicating their potential impact. Immediate action is recommended to mitigate risks associated with these vulnerabilities.

Key Points: • Multiple critical vulnerabilities in python310 have been patched, affecting SUSE systems. • CVE-2026-0864 allows for configuration file injection, while CVE-2026-3276 enables DoS attacks. • Administrators should apply the latest patches immediately to secure their systems.

ThreatCluster AI How this analysis works

Timeline

2026-05-11
CVE-2026-7210 published
Insufficient entropy in XML parsers can lead to hash-flooding attacks, affecting various applications.
Linuxsecurity
2026-05-13
CVE-2026-8328 published
The ftpcp() function in python310 does not validate the peer address, leading to potential security risks.
Linuxsecurity
2026-06-03
CVE-2026-3276 published
Quadratic complexity in unicodedata.normalize() can lead to denial-of-service when processing crafted Unicode input.
Linuxsecurity
2026-06-04
CVE-2026-7774 published
Path traversal bypass in tarfile.data_filter allows writing outside the extraction directory, posing a security risk.
Linuxsecurity
2026-06-23
CVE-2026-0864 published
Improper handling of line-ending characters in the configparser module can lead to configuration file injection.
Linuxsecurity
2026-06-23
CVE-2026-11940 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-4360 published
The filter parameter in Tarfile.extract() is improperly handled, potentially leading to security risks.
Linuxsecurity
2026-08-07
Patch released for python310 vulnerabilities
SUSE released an important update addressing multiple vulnerabilities in python310, urging immediate application of patches.
Linuxsecurity

Community

Browse all →