openSUSE-SU-2026:21159-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21159-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21159-1
Upstream
CVE (3)
Related
Published
2026-06-25T15:31:46Z
Modified
2026-06-30T18:24:46Z
Summary
Security update for python-py7zr
Details

This update for python-py7zr fixes the following issues:

Changes in python-py7zr:

  • CVE-2026-23879: crafted malicious symbolic link chains in an archive can lead to an arbitrary file write (bsc#1268669)
  • CVE-2026-55195: unchecked extraction size can cause a denial of service (bsc#1268665)
  • CVE-2026-55206: crafted .7z archive with a large numstreams value can cause a denial of service (bsc#1268666)
References

Affected packages

openSUSE:Leap 16.0 / python-py7zr

Package

Name
python-py7zr
Purl
pkg:rpm/opensuse/python-py7zr&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.0-bp160.2.1

Ecosystem specific

{
    "binaries":  [
        {
            "python313-py7zr":  "1.0.0-bp160.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21159-1.json"