openSUSE Tumbleweed Ships Virtualenv Update Fixing Four Python Packaging Vulnerabilities
openSUSE has published advisory openSUSE-SU-2026:11974-1, rated moderate, covering four vulnerabilities resolved in the virtualenv packages carried on openSUSE Tumbleweed GA media. The affected packages are python313-virtualenv and python314-virtualenv, both fixed at version 21.14.2-1.1. Four CVEs are referenced: CVE-2024-9287, CVE-2026-102925, CVE-2026-102930 and CVE-2026-102938, with SUSE-assigned scores ranging from 5.3 to 7.7. openSUSE Tumbleweed is the only product listed as affected.
The advisory publishes no exploitation details, root-cause analysis or proof-of-concept code for any of the four issues, and the only technical signal available is the scoring. CVE-2024-9287 is scored as a local attack requiring high privileges and user interaction. CVE-2026-102925 is also local but requires no privileges, with full confidentiality, integrity and availability impact. CVE-2026-102930 is the only network-reachable issue at 7.5 under CVSS v3.1 and 7.7 under v4.0, though it is rated high complexity and still depends on a user acting. CVE-2026-102938 is local, needs low privileges, and affects confidentiality and integrity only.
The practical consequence for openSUSE Tumbleweed users is that systems still running an older snapshot carry all four unresolved flaws, one of which openSUSE scores as network-reachable at 7.7 under CVSS v4.0. openSUSE itself rates the advisory as moderate, and the remaining three issues require local access to the system. Exploitation probability is low across the set: FIRST EPSS places CVE-2024-9287 at 0.6 percent over the next 30 days, CVE-2026-102925 and CVE-2026-102930 at 0.2 percent, and CVE-2026-102938 at 0.1 percent. None of the four appears in CISA's Known Exploited Vulnerabilities catalogue, and no in-the-wild activity is described.
Attack Surface
Endpoint OS, Supply Chain (Third-party vendors)
Tactics
Execution, Initial Access
Techniques
- T1059.006 – Command and Scripting Interpreter: Python
- T1195.002 – Supply Chain Compromise: Compromise Software Supply Chain
- T1574 – Hijack Execution Flow
SuperPRO's Threat Countermeasures Procedures
- Install the fixed packages named in openSUSE-SU-2026:11974-1 on every openSUSE Tumbleweed host: python313-virtualenv 21.14.2-1.1 and python314-virtualenv 21.14.2-1.1, using 'zypper refresh && zypper dup' so the Tumbleweed snapshot moves to the GA media carrying these builds.
- Inventory exposure before patching with 'rpm -q python313-virtualenv python314-virtualenv' and 'zypper search -s virtualenv' across developer workstations, CI runners and build servers, flagging any version below 21.14.2-1.1.
- Rebuild Tumbleweed-based container images and golden images that bundle python313-virtualenv or python314-virtualenv, since running 'zypper dup' on hosts does not refresh virtualenv copies already baked into image layers.
- Recreate Python virtual environments that were generated by the vulnerable virtualenv builds rather than reusing them, and verify the in-venv version with 'pip show virtualenv' inside each environment.
- Because CVE-2024-9287 and CVE-2026-102938 are scored as local issues requiring privileges or user interaction, enumerate what the vulnerable builds installed with 'rpm -ql python313-virtualenv python314-virtualenv' and restrict execution of the virtualenv entry point to administrative accounts on shared Tumbleweed hosts until the 21.14.2-1.1 builds are in place.
- Verify package authenticity after download with 'rpm -K' against the openSUSE signing key, and subscribe the patch management team to [email protected] so follow-up advisory IDs for virtualenv are picked up on the same cycle.