SUSE SLES15: libpython3_9-1_0 / python39 / python39-base / python39-curses / etc (SUSE-SU-2026:4174-1)

high Nessus Plugin ID 346216

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4174-1 advisory.

Security issues fixed:

- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066).
- CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1274743).
- CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788).
- CVE-2026-13346: Arbitrary file installation via malicious package indexes (bsc#1273090 bsc#1273091 bsc#1273094).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192).

Non security issues fixed:

- crypto-policies: Extend the crypto-policies support for mozilla-nss, openjdk, krb5, bind, stunnel, openssh, libssh and more packages (bsc#1211301).
- Update bundled pip wheels to pip-20.0.2-py2.py3-none-any.whl

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1211301

https://bugzilla.suse.com/1262429

https://bugzilla.suse.com/1267581

https://bugzilla.suse.com/1267821

https://bugzilla.suse.com/1269066

https://bugzilla.suse.com/1269788

https://bugzilla.suse.com/1269959

https://bugzilla.suse.com/1271192

https://bugzilla.suse.com/1273090

https://bugzilla.suse.com/1273091

https://bugzilla.suse.com/1273094

https://bugzilla.suse.com/1274743

https://bugzilla.suse.com/1276903

https://bugzilla.suse.com/1277271

https://www.suse.com/security/cve/CVE-2026-0864

https://www.suse.com/security/cve/CVE-2026-11972

https://www.suse.com/security/cve/CVE-2026-13346

https://www.suse.com/security/cve/CVE-2026-15308

https://www.suse.com/security/cve/CVE-2026-1703

https://www.suse.com/security/cve/CVE-2026-3219

https://www.suse.com/security/cve/CVE-2026-3276

https://www.suse.com/security/cve/CVE-2026-4360

https://www.suse.com/security/cve/CVE-2026-7774

http://www.nessus.org/u?c731b8fe

Plugin Details

Severity: High

ID: 346216

File Name: suse_SU-2026-4174-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/16/2026

Updated: 9/16/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.84

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-13346

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-15308

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:libpython3_9-1_0, p-cpe:/a:novell:suse_linux:python39-base, p-cpe:/a:novell:suse_linux:python39-curses, p-cpe:/a:novell:suse_linux:python39-dbm, p-cpe:/a:novell:suse_linux:python39

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/14/2026

Vulnerability Publication Date: 2/2/2026

Reference Information

CVE: CVE-2026-0864, CVE-2026-11972, CVE-2026-13346, CVE-2026-15308, CVE-2026-1703, CVE-2026-3219, CVE-2026-3276, CVE-2026-4360, CVE-2026-7774

IAVA: 2026-A-0549-S

SuSE: SUSE-SU-2026:4174-1