SUSE 5596 Published by

openSUSE has released two moderate security updates for Python packages on Tumbleweed GA media to address recent vulnerabilities. Users running python311 must upgrade to version 3.11.15 to resolve the high severity issue identified as CVE-2026-1299. Meanwhile, a different advisory targets python313 users who must install version 3.13.12 to patch the vulnerability known as CVE-2026-2297.

openSUSE-SU-2026:10398-1: moderate: python311-3.11.15-3.1 on GA media
openSUSE-SU-2026:10394-1: moderate: python313-3.13.12-2.1 on GA media




openSUSE-SU-2026:10398-1: moderate: python311-3.11.15-3.1 on GA media


# python311-3.11.15-3.1 on GA media

Announcement ID: openSUSE-SU-2026:10398-1
Rating: moderate

Cross-References:

* CVE-2026-1299

CVSS scores:

* CVE-2026-1299 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2026-1299 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python311-3.11.15-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311 3.11.15-3.1
* python311-32bit 3.11.15-2.1
* python311-curses 3.11.15-3.1
* python311-dbm 3.11.15-3.1
* python311-idle 3.11.15-3.1
* python311-tk 3.11.15-3.1
* python311-x86-64-v3 3.11.15-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-1299.html



openSUSE-SU-2026:10394-1: moderate: python313-3.13.12-2.1 on GA media


# python313-3.13.12-2.1 on GA media

Announcement ID: openSUSE-SU-2026:10394-1
Rating: moderate

Cross-References:

* CVE-2026-2297

CVSS scores:

* CVE-2026-2297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-2297 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python313-3.13.12-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313 3.13.12-2.1
* python313-32bit 3.13.12-2.1
* python313-curses 3.13.12-2.1
* python313-dbm 3.13.12-2.1
* python313-idle 3.13.12-2.1
* python313-tk 3.13.12-2.1
* python313-x86-64-v3 3.13.12-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-2297.html