Security update for python-h11, python-httpcore
Announcement ID: | SUSE-SU-2025:20330-1 |
---|---|
Release Date: | May 20, 2025, 8:39 a.m. |
Rating: | critical |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves one vulnerability can now be installed.
Description:
This update for python-h11, python-httpcore fixes the following issues:
python-h11: - Update 0.16.0: * CVE-2025-43859: Fixed accepting of malformed Chunked-Encoding bodies (bsc#1241872) - 0.15.0: * Reject Content-Lengths >= 1 zettabyte (1 billion terabytes) early, without attempting to parse the integer (#181)
python-httpcore: - CVE-2025-43859: Fixed accepting of malformed Chunked-Encoding bodies (bsc#1241872)
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Micro 6.1
zypper in -t patch SUSE-SLE-Micro-6.1-114=1
Package List:
-
SUSE Linux Micro 6.1 (noarch)
- python311-h11-0.16.0-slfo.1.1_1.1
- python311-httpcore-0.16.3-slfo.1.1_2.1