Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:4165 - Security Advisory
Issued:
2026-03-10
Updated:
2026-03-10

RHSA-2026:4165 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: python3.12 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3.12 is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
  • cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)
  • cpython: email header injection due to unquoted newlines (CVE-2026-1299)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
  • BZ - 2432437 - CVE-2026-1299 cpython: email header injection due to unquoted newlines

CVEs

  • CVE-2025-15366
  • CVE-2025-15367
  • CVE-2026-1299

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
python3.12-3.12.12-4.el9_7.1.src.rpm SHA-256: 5fa971ae08c44c59bee11855de099a683c81b02bc3c6f94be7b7efae0508a83f
x86_64
python3.12-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 320e0811e1a64e9ac607c666b41d69fbd9917cf83befd52d88cf55396a2f0f6b
python3.12-debuginfo-3.12.12-4.el9_7.1.i686.rpm SHA-256: e9aa156d5dc9c08cfb45e28d20cd78db0bc607b0fa8b2aac06ae233a1526e015
python3.12-debuginfo-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 60d3635ef5d3495ed770dd70ac9f2cbb1ba23e95de1c7a2cf33bfd906c993d52
python3.12-debugsource-3.12.12-4.el9_7.1.i686.rpm SHA-256: 47c45392cd76a791f42c155dfd07c2a7e5a3fd4f6575203815709a4f06be9d6d
python3.12-debugsource-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 7a837a8d3e1a9deec263933da2e8fc0410e4aa666e0d7e677acbb48dc79efa3f
python3.12-devel-3.12.12-4.el9_7.1.i686.rpm SHA-256: 4858c4f914e41c13c0235bb29df78ad719865d2140fc394f1a8434803331b296
python3.12-devel-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: e3805fb4876aab3183cf972175b9279932f410ca515ab4e53a1f3082228e6110
python3.12-libs-3.12.12-4.el9_7.1.i686.rpm SHA-256: 8f8d4f1eace26cfeec971e9685f67ea8c7e889de02e47506a256ff1a6eeee051
python3.12-libs-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 3c63141ada03d7512b5e068309d0a067503601d9dfae060dd06dd69478943b82
python3.12-tkinter-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 58e4351105c7e9a6f5b8600bb063038cca0b88c1db187547d41a35f5cf5b2348

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
python3.12-3.12.12-4.el9_7.1.src.rpm SHA-256: 5fa971ae08c44c59bee11855de099a683c81b02bc3c6f94be7b7efae0508a83f
s390x
python3.12-3.12.12-4.el9_7.1.s390x.rpm SHA-256: 0571271237e964c415a1e250b2231a661593ab624634df7bda88b437798015a0
python3.12-debuginfo-3.12.12-4.el9_7.1.s390x.rpm SHA-256: aa390b7e85fdab87fc74b05e7e3aa7ba840ff76934e1ce583e5eade6fb59287c
python3.12-debugsource-3.12.12-4.el9_7.1.s390x.rpm SHA-256: 38b01eef6fa90157847cf5239162744e6a59941e8e738798b669d57440111720
python3.12-devel-3.12.12-4.el9_7.1.s390x.rpm SHA-256: 98878a74a20591a8e3f6f7b8eb4204f18104782791d79364412ebe1eb7c51b38
python3.12-libs-3.12.12-4.el9_7.1.s390x.rpm SHA-256: 9ff71df093ae61b010222e30821e0044c42e92c7e8f69c0d6574ac0e30ca21e1
python3.12-tkinter-3.12.12-4.el9_7.1.s390x.rpm SHA-256: eeb02f839338571219132856c611336ba597c4609fd5af690d92d2adfab4e6c2

Red Hat Enterprise Linux for Power, little endian 9

SRPM
python3.12-3.12.12-4.el9_7.1.src.rpm SHA-256: 5fa971ae08c44c59bee11855de099a683c81b02bc3c6f94be7b7efae0508a83f
ppc64le
python3.12-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: bbdb5fd1db7376531291fccbdbc6054e215e7c27c7c1c7be4811a4890ff49b51
python3.12-debuginfo-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: c637b4d612275317223a21d7119ef7585399999abef16749a6ffd8e8ae596e71
python3.12-debugsource-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: acc8b4e67d4e77e66da72c34bef61abf52a705719006114db021bf7bba3f9fa6
python3.12-devel-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: 0a7621103283ff2e415fd592ae295e89395bc0138c3707200b18e03ac56d4dea
python3.12-libs-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: 818cae0b74e9d7c65f599e42d39241588d50332103be6a1995722b32ad3dce37
python3.12-tkinter-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: e1de384bfda1c25e305054fd259298c146e03792843ace1a9d6536065e874777

Red Hat Enterprise Linux for ARM 64 9

SRPM
python3.12-3.12.12-4.el9_7.1.src.rpm SHA-256: 5fa971ae08c44c59bee11855de099a683c81b02bc3c6f94be7b7efae0508a83f
aarch64
python3.12-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: 0d360b72d46221e6c67bf4911523c7f63ce394e1d10d33d0ed1fe1f584989781
python3.12-debuginfo-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: dac715ce383bdde9347c862e32a5b31e2b322c32a643d69092324bdb2fe9e14e
python3.12-debugsource-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: e7e87d54f4e5722955d7b184ebb18e1f675ef45f0327a7332e3b1e50a02d7802
python3.12-devel-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: 8af12147aaa269686e10cf612df6bcdbdb9b979c06d0493dadba04fcbc2d0807
python3.12-libs-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: 79f41e3b0dc48884c4d7de8339ba9462862e645d5a53a2f61f970469c1a70395
python3.12-tkinter-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: 3064f2e9dcbef3ca845a258358815d7d1b066ce7879d4a3c571208acb9639ff8

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
python3.12-3.12.12-4.el9_7.1.i686.rpm SHA-256: 007e190792e7f5b7956bab38e5fb5cc023b5dd2e90898c0901d7b1fd6db92b65
python3.12-debug-3.12.12-4.el9_7.1.i686.rpm SHA-256: a741b2ce289d328827d4e3735bafac454a64ddb9d1afede2a30b32de01197974
python3.12-debug-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 06d6709d98571c57f21ddaead86e6de0631a5cd319cb323da2b362dfa7d2ffe4
python3.12-debuginfo-3.12.12-4.el9_7.1.i686.rpm SHA-256: e9aa156d5dc9c08cfb45e28d20cd78db0bc607b0fa8b2aac06ae233a1526e015
python3.12-debuginfo-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 60d3635ef5d3495ed770dd70ac9f2cbb1ba23e95de1c7a2cf33bfd906c993d52
python3.12-debugsource-3.12.12-4.el9_7.1.i686.rpm SHA-256: 47c45392cd76a791f42c155dfd07c2a7e5a3fd4f6575203815709a4f06be9d6d
python3.12-debugsource-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 7a837a8d3e1a9deec263933da2e8fc0410e4aa666e0d7e677acbb48dc79efa3f
python3.12-idle-3.12.12-4.el9_7.1.i686.rpm SHA-256: 877720bda6c9d10dcf6b9df315af1a6f8428739dd9d50855d1df5602c4c91e76
python3.12-idle-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: f62eff2219b3bb10a3136d6bed56dd432c08cdbbd84a0e3eedb3c4114d6fd633
python3.12-test-3.12.12-4.el9_7.1.i686.rpm SHA-256: be7a4a78a1b4184666c5700623d1d41698979c87cab266673f071616167fa3cf
python3.12-test-3.12.12-4.el9_7.1.x86_64.rpm SHA-256: 817a233f56c7ca6455f9efb7993e4ad467f07a10098f0e543021b68efdcffa03
python3.12-tkinter-3.12.12-4.el9_7.1.i686.rpm SHA-256: 142e43fbd747a309eea5c3b0500f7bca81d2ca4104e4cf1f5c258a40605a0884

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
python3.12-debug-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: e40f20675f0bd86e7ba8f70c0d8bc3d1e58e4d9a8bb470b404a121fab8cf546d
python3.12-debuginfo-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: c637b4d612275317223a21d7119ef7585399999abef16749a6ffd8e8ae596e71
python3.12-debugsource-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: acc8b4e67d4e77e66da72c34bef61abf52a705719006114db021bf7bba3f9fa6
python3.12-idle-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: 6d26c84516d305641bb058d23887edafee80352f25669dde0ca0cc7d14cb3efd
python3.12-test-3.12.12-4.el9_7.1.ppc64le.rpm SHA-256: b3c5a7279bf9ac8e6ea63c5afa81e720825553f4ba32f7a232772624c65740db

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
python3.12-debug-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: 80d23eeac67f9945291863c8551aad8c871379bc5dd75461beb0505876a430e6
python3.12-debuginfo-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: dac715ce383bdde9347c862e32a5b31e2b322c32a643d69092324bdb2fe9e14e
python3.12-debugsource-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: e7e87d54f4e5722955d7b184ebb18e1f675ef45f0327a7332e3b1e50a02d7802
python3.12-idle-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: 894f89f372d2a5757e42fcb7c451872dba967682700de15ef2cb20d7fb69769c
python3.12-test-3.12.12-4.el9_7.1.aarch64.rpm SHA-256: ec18a56c844e880d06b6262979bd93dfee2e8f6142610fd56ae85a0c43d85ebb

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
python3.12-debug-3.12.12-4.el9_7.1.s390x.rpm SHA-256: 27c79956605c50dfea90a71927717f4f15f0faa8a456fb7b1ced87a1bffec741
python3.12-debuginfo-3.12.12-4.el9_7.1.s390x.rpm SHA-256: aa390b7e85fdab87fc74b05e7e3aa7ba840ff76934e1ce583e5eade6fb59287c
python3.12-debugsource-3.12.12-4.el9_7.1.s390x.rpm SHA-256: 38b01eef6fa90157847cf5239162744e6a59941e8e738798b669d57440111720
python3.12-idle-3.12.12-4.el9_7.1.s390x.rpm SHA-256: 4253395ec12b8b10312e5c4eb2eafb7efdb0fc96395969bb1473abae614b6cb3
python3.12-test-3.12.12-4.el9_7.1.s390x.rpm SHA-256: b2aca1fb2234d91c525bf1fb435f55d8ecafdec5c6345575308b681786b5bcd0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility