SUSE-SU-2025:4257-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-20254257-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:4257-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2025:4257-1
Upstream
CVE (2)
Related
Published
2025-11-26T13:43:01Z
Modified
2026-03-11T07:31:04Z
Summary
Security update for python311
Details

This update for python311 fixes the following issues:

Update to 3.11.14:

  • CVE-2025-6075: Fixed simple quadratic complexity vulnerabilities of os.path.expandvars() (bsc#1252974)
  • CVE-2025-8291: Fixed validity of the ZIP64 End of Central Directory (EOCD) not checked by the 'zipfile' module (bsc#1251305)
References

Affected packages

SUSE:Linux Enterprise Module for Public Cloud 15 SP4
python311

Package

Name
python311
Purl
pkg:rpm/suse/python311&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.14-150400.9.69.1

Ecosystem specific

{
    "binaries":  [
        {
            "libpython3_11-1_0":  "3.11.14-150400.9.69.1",
            "python311":  "3.11.14-150400.9.69.1",
            "python311-base":  "3.11.14-150400.9.69.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:4257-1.json"
python311-core

Package

Name
python311-core
Purl
pkg:rpm/suse/python311-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.11.14-150400.9.69.1

Ecosystem specific

{
    "binaries":  [
        {
            "libpython3_11-1_0":  "3.11.14-150400.9.69.1",
            "python311":  "3.11.14-150400.9.69.1",
            "python311-base":  "3.11.14-150400.9.69.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:4257-1.json"