Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:11091 - Security Advisory
Issued:
2024-12-16
Updated:
2024-12-16

RHSA-2024:11091 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: python36:3.6 security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the python36:3.6 module is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • virtualenv: potential command injection via virtual environment activation scripts (CVE-2024-53899)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64

Fixes

  • BZ - 2328554 - CVE-2024-53899 virtualenv: potential command injection via virtual environment activation scripts

CVEs

  • CVE-2024-53899

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 8.2

SRPM
python-PyMySQL-0.8.0-10.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: dfe6679ee9c5804bc32b99f0bf68d7fd7f9a9d960c7943aa90aa5f55cd763a67
python-distro-1.4.0-2.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: 1f94006aa183de18089198dbea452628c14dc1ad89d55ac89ec43f9d7c193900
python-docs-3.6.7-2.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: 02d53815304d5fc8141d10815cc6f79e52f2c7556e4cc1aaf6db986adead2672
python-docutils-0.14-12.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: c68b82e47754e15d7917c392cb6c1eb50d3642a82ed0bf2536c540163a5779ee
python-nose-1.3.7-30.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: fab2af705910c9eabc132787394c2476330a48bd3a878606d453fb0fdb441ea0
python-pygments-2.2.0-20.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: be9bf57a26e4592076c32aca9675dc0f565eb1462d14545967194d78619e2d53
python-pymongo-3.6.1-11.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: 6af92f839cd35de87781efca97500e06267a1dc6e46f687019b8c9e80c7e4cb3
python-sqlalchemy-1.3.2-1.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: cfe7152f0d5680633e59bb99842f0ac4fcbd3c11e28eec34868ded86315d5306
python-virtualenv-15.1.0-19.module+el8.2.0+22651+db2d74c8.2.src.rpm SHA-256: a906146c5d9796cc86e90fa3913c4a5d5d126980bb94f1c7837bafca55c1a0f0
python-wheel-0.31.1-2.module+el8.1.0+3724+3c097090.src.rpm SHA-256: 6e005db82d39685c6b7fca19dc4a4369598236c27cb1613a4aa4c4ef380d1fac
python36-3.6.8-2.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: a38bfd696fe1bac41e661fbed4fc684cbe57733e9a0dc91c71e184255d768b96
scipy-1.0.0-20.module+el8.1.0+3334+5cb623d7.src.rpm SHA-256: e5907742d6e0d80dd78e0114f005c0ad9002e492b3dc62ce9b731117e13eb909
x86_64
python-nose-docs-1.3.7-30.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: d536d862398eb842f3abfb5e183919beefbc5e5027b536be8273dcc47358af0e
python-pymongo-debuginfo-3.6.1-11.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: e9e736c051f946cb400a0fb0fa14ee46ad6fa57ca750cffb90ffde9540eed2f6
python-pymongo-debugsource-3.6.1-11.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 3f686f908d57e9127be2cfbaa400b4d7e73cc9fcb496990efed8fbe0bf458481
python-pymongo-doc-3.6.1-11.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: f6f13e94c2ef0fbc7e4b8c20e69f7abc01e22ba22be3d95307f7cab581cad6e4
python-sqlalchemy-doc-1.3.2-1.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: adf2b4feb61458410eae86b8cd8cefc51279aab001bbf7ba9ed72418a4b00df2
python-virtualenv-doc-15.1.0-19.module+el8.2.0+22651+db2d74c8.2.noarch.rpm SHA-256: a2a72d2bebd170d32cb02eff6375ec5d81cbb7618e25bfb132d04dc3608661c8
python3-PyMySQL-0.8.0-10.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: 4fa8aea364c7e4d9abb75d4e4f9cbfa65b96866218a948a01bf6db051a4b3638
python3-bson-3.6.1-11.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 252b308055cd5dfdadc0b30d3c55e4f3174c98a40b6b4bb698a98c1fee7e3534
python3-bson-debuginfo-3.6.1-11.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 86ae462038007cd9d16cd33070f4e6efbcf8e4b85c70c2c9ef8d01657f85f323
python3-distro-1.4.0-2.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: ea1f36590d771be525d98f5e46384300bc6041a91ffc08d20794dbe464f293f1
python3-docs-3.6.7-2.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: 45556da40bbdc828fe0b393d3728152e32e2f563e6cab07f76acee054efca411
python3-docutils-0.14-12.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: a54402bcbae0fded4ef0726397793f4905b58815845c28a8c408025d8cbf9adb
python3-nose-1.3.7-30.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: 66bd57ed1454e162b859788d32717e99a1ddc6da3ae44a32539bc0c5f389010e
python3-pygments-2.2.0-20.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: 30354341eab343209fb0c2474fb386760356a60e4583fcbce1f90113436a2383
python3-pymongo-3.6.1-11.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 36a4afffbc0bf0e6196d83d29a8f9dc70dede4102a5f6393a43296b2ba9da961
python3-pymongo-debuginfo-3.6.1-11.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: c073d2c4fed93d1b96baccc6dc6027910c66c35e4c8521cfd66afd17cc78a2cf
python3-pymongo-gridfs-3.6.1-11.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 67d9930f1edd75fbb88a1c29b5708aee94002128c562f0ce9f3255e76cd87d5e
python3-scipy-1.0.0-20.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 4e5b9ef35d6c3fbef8b7bf526f8160a49452b559eaaa0d3d9fe66d4688936486
python3-scipy-debuginfo-1.0.0-20.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 34030893e767a74179fc9f5fabf90399f0043cefe4ed8bda89b75c8b7fde9de1
python3-sqlalchemy-1.3.2-1.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: bc58fa5b26e14b090d594aefc18bad714629ddab4d8176022d6d92cfd25dda5f
python3-virtualenv-15.1.0-19.module+el8.2.0+22651+db2d74c8.2.noarch.rpm SHA-256: 340b06256b224ac65054f48611314b940740916075983ca6caab2286591510a1
python3-wheel-0.31.1-2.module+el8.1.0+3724+3c097090.noarch.rpm SHA-256: beece528f83a10b638c30d1e25ee3c0bec7d70e254afd4b98a2440d3279205f8
python3-wheel-wheel-0.31.1-2.module+el8.1.0+3724+3c097090.noarch.rpm SHA-256: bdc7ea7e12c898dc3bb14aa887b85cfc9f7457256c7a292ac07e43dd314cb5f6
python36-3.6.8-2.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 9e70cafe666de95febf05bcee7d3be9a2c5cb9bb3d361d81b2d72bde8a5e20c7
python36-debug-3.6.8-2.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: f68d62a0fde63bf502ebd5a2c740bff6a89ef6f14f98cbea023ae301fd6657ca
python36-devel-3.6.8-2.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 4f1e16fd0f5f5442b937f6bc2de2ac86660884cfe2eac1f651b2ea493a36cd22
python36-rpm-macros-3.6.8-2.module+el8.1.0+3334+5cb623d7.noarch.rpm SHA-256: 35edf8d6c276078d9a04a563961ed8a5e340f6a7ab90365fc27caf2c95608147
scipy-debugsource-1.0.0-20.module+el8.1.0+3334+5cb623d7.x86_64.rpm SHA-256: 3177060bd37ee5c98490204a1b0fcf2bc5e347e50cea5e4b10532f2257173028

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility