SUSE SLES15: libpython3_10-1_0 / python310 / python310-base / python310-curses / etc (SUSE-SU-2026:3530-1)

high Nessus Plugin ID 333543

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3530-1 advisory.

Security issues fixed:

- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash- flooding protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192).

Non security issues fixed:

- [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).
- crypto-policies: Extend the crypto-policies support for mozilla-nss, openjdk, krb5, bind, stunnel, openssh, libssh and more packages (bsc#1211301).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1211301

https://bugzilla.suse.com/1264962

https://bugzilla.suse.com/1265268

https://bugzilla.suse.com/1267581

https://bugzilla.suse.com/1267821

https://bugzilla.suse.com/1268375

https://bugzilla.suse.com/1268977

https://bugzilla.suse.com/1269066

https://bugzilla.suse.com/1269788

https://bugzilla.suse.com/1269959

https://bugzilla.suse.com/1271192

https://www.suse.com/security/cve/CVE-2026-0864

https://www.suse.com/security/cve/CVE-2026-11940

https://www.suse.com/security/cve/CVE-2026-11972

https://www.suse.com/security/cve/CVE-2026-15308

https://www.suse.com/security/cve/CVE-2026-3276

https://www.suse.com/security/cve/CVE-2026-4360

https://www.suse.com/security/cve/CVE-2026-7210

https://www.suse.com/security/cve/CVE-2026-7774

https://www.suse.com/security/cve/CVE-2026-8328

http://www.nessus.org/u?8ed7e60b

Plugin Details

Severity: High

ID: 333543

File Name: suse_SU-2026-3530-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/9/2026

Updated: 8/9/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.67

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-4360

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-15308

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:libpython3_10-1_0, p-cpe:/a:novell:suse_linux:python310-base, p-cpe:/a:novell:suse_linux:python310-curses, p-cpe:/a:novell:suse_linux:python310-dbm, p-cpe:/a:novell:suse_linux:python310-devel, p-cpe:/a:novell:suse_linux:python310-idle, p-cpe:/a:novell:suse_linux:python310-tk, p-cpe:/a:novell:suse_linux:python310-tools, p-cpe:/a:novell:suse_linux:python310

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/7/2026

Vulnerability Publication Date: 5/11/2026

Reference Information

CVE: CVE-2026-0864, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-3276, CVE-2026-4360, CVE-2026-7210, CVE-2026-7774, CVE-2026-8328

IAVA: 2026-A-0549

SuSE: SUSE-SU-2026:3530-1