SUSE alert openSUSE-SU-2026:0102-1 (python-pydicom)
| From: | maintenance@opensuse.org | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:0102-1: important: Security update for python-pydicom | |
| Date: | Fri, 27 Mar 2026 21:05:06 +0100 | |
| Message-ID: | <20260327200506.3F198FD1A@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE Security Update: Security update for python-pydicom ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0102-1 Rating: important References: #1259973 Cross-References: CVE-2026-32711 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-pydicom fixes the following issues: - CVE-2026-32711: path traversal in FileSet/DICOMDIR ReferencedFileID can allow file access outside the File-set root (boo#1259973) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-102=1 Package List: - openSUSE Backports SLE-15-SP7 (noarch): python3-pydicom-2.3.1-bp157.2.3.1 python311-pydicom-2.3.1-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2026-32711.html https://bugzilla.suse.com/1259973
