openSUSE-SU-2026:20199-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20199-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20199-1
Upstream
Related
Published
2026-02-11T16:38:19Z
Modified
2026-03-23T04:54:47Z
Summary
Security update for micropython
Details

This update for micropython fixes the following issues:

Changes in micropython:

  • CVE-2026-1998: Fixed segmentation fault in mp_map_lookup via mp_import_all (bsc#1257803).

  • Version 1.26.1

    • esp32: update esp_tinyusb component to v1.7.6
    • tools: add an environment variable MICROPY_MAINTAINER_BUILD
    • esp32: add IDF Component Lockfiles to git repo
    • shared/tinyusb: fix hang from new tx_overwritabe_if_not_connected flag
    • shared/tinyusb/mp_usbd_cdc: rewrite USB CDC TX loop
    • tools/mpremote: don't apply Espressif DTR/RTS quirk to TinyUSB CDC dev
  • Fix building on single core systems

    • Skip tests/thread/stress_schedule.py when single core system detected
References

Affected packages

openSUSE:Leap 16.0 / micropython

Package

Name
micropython
Purl
pkg:rpm/opensuse/micropython&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.26.1-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "micropython":  "1.26.1-bp160.1.1",
            "mpremote":  "1.26.1-bp160.1.1",
            "mpy-tools":  "1.26.1-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20199-1.json"