Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5219 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5219 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: python3.9 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3.9 is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
  • cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)
  • cpython: email header injection due to unquoted newlines (CVE-2026-1299)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
  • BZ - 2432437 - CVE-2026-1299 cpython: email header injection due to unquoted newlines

CVEs

  • CVE-2025-15366
  • CVE-2025-15367
  • CVE-2026-1299

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
python3.9-3.9.10-4.el9_0.9.src.rpm SHA-256: cd654a0d171c06062fa9b99eb664666c93f345b7ac64b536d7d85100d83b1894
ppc64le
python-unversioned-command-3.9.10-4.el9_0.9.noarch.rpm SHA-256: 38e69bdf75e5f56809f65ac0498a39fcb1583ac217c8510ad72a9a0f7a0b5ed0
python3-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: 3b0567956dc4f91bce7591ea60be8b6b67c8603b8ccf27e633aa15e64265a259
python3-devel-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: 3ec18309c9470705721f53da4c9e0e54aadec7fc56639e546542e6162344d59c
python3-libs-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: fd13745041c56d9026cc463846355be4302e793804cc32d851c6418d4bada3e8
python3-tkinter-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: 86a2b192e6a23fcfb5a2c4c2b6a8d647cf67346f0d0998eda4684b489284417f
python3.9-debuginfo-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: 6331576cf0a4f44a4acd3a0776ed9113cdaf1b5263c789b5ac464e6d9ba643d8
python3.9-debuginfo-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: 6331576cf0a4f44a4acd3a0776ed9113cdaf1b5263c789b5ac464e6d9ba643d8
python3.9-debugsource-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: 05e1879745f7e3c3455d971865226b3c64ab3cc888eae646deeb9383a1256007
python3.9-debugsource-3.9.10-4.el9_0.9.ppc64le.rpm SHA-256: 05e1879745f7e3c3455d971865226b3c64ab3cc888eae646deeb9383a1256007

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
python3.9-3.9.10-4.el9_0.9.src.rpm SHA-256: cd654a0d171c06062fa9b99eb664666c93f345b7ac64b536d7d85100d83b1894
x86_64
python-unversioned-command-3.9.10-4.el9_0.9.noarch.rpm SHA-256: 38e69bdf75e5f56809f65ac0498a39fcb1583ac217c8510ad72a9a0f7a0b5ed0
python3-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: 96ec7c85a2d54045a4523fa2ef4b703b4a7c80e9d4be602e4b007ce5e4385f76
python3-devel-3.9.10-4.el9_0.9.i686.rpm SHA-256: 0e5ef7dd28cede3326b205b3a7867b89b034d5da9401c196cbf0696f256b5aa9
python3-devel-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: 71fdd41951292c339d38d9c8aebc0cac66ebbf386c37ab5ea7c3f21049b5a721
python3-libs-3.9.10-4.el9_0.9.i686.rpm SHA-256: c2d50dabda139e2c43ab74f428ca60e3f11784bd526cd7f690032193bb20335f
python3-libs-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: 76183c5d6e16d126a0fc03f80d41c90a3993dbe309e45df903053267c1a3553b
python3-tkinter-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: 6e3f3a7c09bc7317665b05fb9abd998b09bad8a572146535789fc638225583ab
python3.9-debuginfo-3.9.10-4.el9_0.9.i686.rpm SHA-256: 46dbb4956292d300089c761e1a923ccb9c4e3b170f3543a0eeadbfdc3c12dd0c
python3.9-debuginfo-3.9.10-4.el9_0.9.i686.rpm SHA-256: 46dbb4956292d300089c761e1a923ccb9c4e3b170f3543a0eeadbfdc3c12dd0c
python3.9-debuginfo-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: f270b52ad13387b676bc09bf22ca94e69b69db8b88e4e022c488ec351cce438d
python3.9-debuginfo-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: f270b52ad13387b676bc09bf22ca94e69b69db8b88e4e022c488ec351cce438d
python3.9-debugsource-3.9.10-4.el9_0.9.i686.rpm SHA-256: 788a474f61c7e3bdda962fafe79fd0e29cba368ede4cc920f762820bfec364ea
python3.9-debugsource-3.9.10-4.el9_0.9.i686.rpm SHA-256: 788a474f61c7e3bdda962fafe79fd0e29cba368ede4cc920f762820bfec364ea
python3.9-debugsource-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: 10216ecc1ee691715201e0f00898183cb8318505d3028c340f90074ab773a675
python3.9-debugsource-3.9.10-4.el9_0.9.x86_64.rpm SHA-256: 10216ecc1ee691715201e0f00898183cb8318505d3028c340f90074ab773a675

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
python3.9-3.9.10-4.el9_0.9.src.rpm SHA-256: cd654a0d171c06062fa9b99eb664666c93f345b7ac64b536d7d85100d83b1894
aarch64
python-unversioned-command-3.9.10-4.el9_0.9.noarch.rpm SHA-256: 38e69bdf75e5f56809f65ac0498a39fcb1583ac217c8510ad72a9a0f7a0b5ed0
python3-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: 1930be036edac051c06b46adde2f467cde097162be3349ff5c1978985f34cf03
python3-devel-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: 7bf85da5c5f4b44839690850e0ce26a0e519b3e68437d457dd59f690bfd8441e
python3-libs-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: da935b40f851b9d4ae53e9e34df1a81d2da02b0c1ffce1ff24be1afbfba1ad4d
python3-tkinter-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: 1fff220cb404f0b2317a35d497765d8f31cbbd5507fda24bc8765353fceb4bfb
python3.9-debuginfo-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: ec44453468ac86cf7494a23aa9a5c96ef3baa261d4152a4895bde7a04023aa44
python3.9-debuginfo-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: ec44453468ac86cf7494a23aa9a5c96ef3baa261d4152a4895bde7a04023aa44
python3.9-debugsource-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: a37e600646dbf7c22cf22ae2066ec469fdcc390260925bb475cd3f6fdd92d071
python3.9-debugsource-3.9.10-4.el9_0.9.aarch64.rpm SHA-256: a37e600646dbf7c22cf22ae2066ec469fdcc390260925bb475cd3f6fdd92d071

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
python3.9-3.9.10-4.el9_0.9.src.rpm SHA-256: cd654a0d171c06062fa9b99eb664666c93f345b7ac64b536d7d85100d83b1894
s390x
python-unversioned-command-3.9.10-4.el9_0.9.noarch.rpm SHA-256: 38e69bdf75e5f56809f65ac0498a39fcb1583ac217c8510ad72a9a0f7a0b5ed0
python3-3.9.10-4.el9_0.9.s390x.rpm SHA-256: 66ad4facdd6ea48f1ae7d60571e91f8e21c19e1429ed9c51bc568113a19b53cc
python3-devel-3.9.10-4.el9_0.9.s390x.rpm SHA-256: 8a06b081ac9d6b3b258fbb929a4c78c819f0e9d3ec1143febf53afe05d76bc91
python3-libs-3.9.10-4.el9_0.9.s390x.rpm SHA-256: d23ced3acd920f1fc9402dc9151c8529e1b8e916a29b015c6441a8a0ae38ef7e
python3-tkinter-3.9.10-4.el9_0.9.s390x.rpm SHA-256: de217cb828cfca284d47e716ec2d6e3db74cc9d22f0e39b86b6478089c994895
python3.9-debuginfo-3.9.10-4.el9_0.9.s390x.rpm SHA-256: 1c5b3726122e2889836c74ddea8d5064b730a57c96c043328ea0bd4c3d010b8f
python3.9-debuginfo-3.9.10-4.el9_0.9.s390x.rpm SHA-256: 1c5b3726122e2889836c74ddea8d5064b730a57c96c043328ea0bd4c3d010b8f
python3.9-debugsource-3.9.10-4.el9_0.9.s390x.rpm SHA-256: bdf368282a6c824be5766ff4a550f8f69564bcd4dc7af003754f9bc0f6365dc5
python3.9-debugsource-3.9.10-4.el9_0.9.s390x.rpm SHA-256: bdf368282a6c824be5766ff4a550f8f69564bcd4dc7af003754f9bc0f6365dc5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility