Linuxsecurity
SUSE Python-httplib2 OOM Vulnerability Disclosed
Article Content
An important vulnerability (CVE-2026-59939) has been identified in the SUSE python-httplib2 package, which can lead to an Out Of Memory (OOM) kill in client processes. This issue arises from unbounded decompression of HTTP response bodies using gzip or deflate encoding when connecting to compromised HTTP servers. Affected systems include SUSE Linux Enterprise Server and openSUSE Leap versions 15.4 and 15-SP4/15-SP5. The vulnerability was published on July 8, 2026, and has a CVSS score of 7.5, indicating a high severity level. Users are advised to apply the latest patches using SUSE's recommended installation methods. The patch addresses the OOM risk and is critical for maintaining system stability and security.
Key Points: • CVE-2026-59939 poses an OOM risk in python-httplib2. • Affected systems include SUSE Linux Enterprise and openSUSE Leap. • Immediate patching is recommended to mitigate the vulnerability.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.