Security update for python-pip
| Announcement ID: | SUSE-SU-2026:22018-1 |
|---|---|
| Release Date: | 2026-06-02T13:37:37Z |
| Rating: | moderate |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves three vulnerabilities can now be installed.
Description:
This update for python-pip fixes the following issues:
- CVE-2026-3219: concatenated tar and ZIP files are handled as ZIP files, resulting in possibly obfuscated malicious code (bsc#1262429).
- CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation, resulting in potential arbitrary code execution (bsc#1263442).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-872=1 -
SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-872=1
Package List:
-
SUSE Linux Enterprise Server 16.0 (noarch)
- python313-pip-wheel-25.0.1-160000.4.1
- python313-pip-25.0.1-160000.4.1
-
SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
- python313-pip-wheel-25.0.1-160000.4.1
- python313-pip-25.0.1-160000.4.1