EulerOS 2.0 SP15 : python3 (EulerOS-SA-2026-3946)

high Nessus Plugin ID 364010

Synopsis

The remote EulerOS host is missing multiple security updates.

Description

According to the versions of the python3 packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

unicodedata.normalize() can take excessive CPU time when processing_x000D_ specially crafted Unicode input containing long runs of combining characters_x000D_ with alternating Canonical Combining Class values._x000D_ This affects all normalization forms.(CVE-2026-3276)

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at its archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.(CVE-2026-11940)

When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use 'validate=True' to enable stricter processing of base64 data.(CVE-2026-3446)

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks.
An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.(CVE-2026-4360)

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.(CVE-2025-15366)

To allow builds of Python to be run from an in-tree layout (rather than_x000D_ an installed file layout), the VPATH variable is defined at build time_x000D_ and used to locate certain landmarks - specifically,_x000D_ Modules/setup.local. When this landmark is found relative to VPATH_x000D_ relative to the executable, Python assumes it is running in a source_x000D_ tree and generates a different default sys.path. This code remains in_x000D_ release builds, so that release-ready builds can be built in-tree._x000D_
_x000D_ On Windows, since builds are written to 'PCbuild/', the value of_x000D_ VPATH is set to '..\..', which results in a landmark of_x000D_ '..\..\Modules\setup.local'. This path is outside the install directory_x000D_ of Python, and may have different permissions, potentially allowing a_x000D_ low-privilege user to create the landmark and an alternative `Lib`_x000D_ folder that will be discovered by an otherwise restricted install._x000D_
_x000D_ Such a setup occurs with the legacy default install location for all_x000D_ users (in the now superseded EXE installer), due to how Windows allows_x000D_ all users to create folders in the root directory of their OS drive._x000D_
_x000D_ Our recommended mitigation on Windows is to migrate away from the_x000D_ legacy installer and use the new [Python install_x000D_ manager](https://www.python.org/downloads/latest/pymanager/) to install_x000D_ for the current user. Installs where the directory two levels above the_x000D_ Python installation directory have equivalent permissions are unaffected_x000D_ (in general, a per-user install cannot be modified at all by other_x000D_ users, removing any escalation of privilege risk, and could be directly_x000D_ modified by a privileged user, making the potential tampering_x000D_ irrelevant). Alternative mitigations might include preemptively creating_x000D_ and restricting access to a `Modules` directory. Be aware that only 3.13_x000D_ and 3.14 will receive updated legacy installers - earlier fixes are only_x000D_ provided as sources._x000D_
_x000D_ Platforms other than Windows allow VPATH to be overridden, but as they_x000D_ don't usually use a separated directory in the build for binaries, are_x000D_ unlikely to have a landmark reference outside of the install directory._x000D_
_x000D_ The landmark detection involving VPATH is a fallback for when a more_x000D_ specific landmark - .\pybuilddir.txt - is absent, and was included for_x000D_ compatibility. Future releases of Python will no longer include the_x000D_ fallback, and so builds will need to generate or preserve the_x000D_ pybuilddir.txt file in order to work in-tree. This landmark file has_x000D_ been generated on Windows since 3.11, and on other platforms for longer.(CVE-2026-12003)

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.(CVE-2026-7210)

When using the 'configparser' module to write configuration files_x000D_ containing multi-line text values with carriage return characters (\r) the_x000D_ resulting file could be injected with unexpected keys and values if the_x000D_ attacker controls the written value.(CVE-2026-0864)

When using the 'tarfile' module with a file opened in 'streaming mode' (mode='r|') the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.(CVE-2026-11972)

The Oracle Solaris Third Party Bulletin announces patches for one or more security vulnerabilities addressed in third party software that is included in Oracle Solaris distributions. Starting January 20, 2015, Third Party Bulletins are released on the same day when Oracle Critical Patch Updates are released.
These bulletins will also be updated after their release between the quarterly Critical Patch Updates. In addition, Third Party Bulletins may also be updated for vulnerability issues deemed too critical to wait for the next monthly update.(CVE-2026-8328)

The incremental HTML parser (html.parser.HTMLParser) allows for CPU_x000D_ denial-of-service through repeated unterminated markup declarations when_x000D_ processing uncontrolled data.(CVE-2026-15308)

Tenable has extracted the preceding description block directly from the EulerOS python3 security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected python3 packages.

See Also

http://www.nessus.org/u?658faf87

Plugin Details

Severity: High

ID: 364010

File Name: EulerOS_SA-2026-3946.nasl

Version: 1.1

Type: Local

Published: 10/8/2026

Updated: 10/8/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.23

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-4360

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-0864

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 8.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-15308

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:python3-devel, p-cpe:/a:huawei:euleros:python3-fgo, p-cpe:/a:huawei:euleros:python3-help, p-cpe:/a:huawei:euleros:python3-unversioned-command, p-cpe:/a:huawei:euleros:python3

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Ease: No known exploits are available

Patch Publication Date: 10/8/2026

Vulnerability Publication Date: 1/20/2026

Reference Information

CVE: CVE-2025-15366, CVE-2026-0864, CVE-2026-11940, CVE-2026-11972, CVE-2026-12003, CVE-2026-15308, CVE-2026-3276, CVE-2026-3446, CVE-2026-4360, CVE-2026-7210, CVE-2026-8328