Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5221 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5221 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: python3 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3 is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
  • cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)
  • cpython: email header injection due to unquoted newlines (CVE-2026-1299)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
  • BZ - 2432437 - CVE-2026-1299 cpython: email header injection due to unquoted newlines

CVEs

  • CVE-2025-15366
  • CVE-2025-15367
  • CVE-2026-1299

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4

SRPM
python3-3.6.8-39.el8_4.9.src.rpm SHA-256: e4269087e71655b6a43539a0def76bbe019709ff68d4f01985f3ff7b4499d153
x86_64
platform-python-3.6.8-39.el8_4.9.i686.rpm SHA-256: b4328a08a028cbe8ee2d2dc703c086300a1e6498d39693b8990d8e9d01bc636e
platform-python-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 776d0203ffa20a528ed6254760483dd5b144f9af92702f02e2b3e2b5d381de27
platform-python-debug-3.6.8-39.el8_4.9.i686.rpm SHA-256: 6d01625b4355ec183e32a6f04a81853e62bc730996cb5f27dbf8ec4f8cffa5cb
platform-python-debug-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 503641026ed29ab56ddf8dc6d94834d1ae4281e3a9a4d09baa1abdd8e2ad54c7
platform-python-devel-3.6.8-39.el8_4.9.i686.rpm SHA-256: e2984b7e1ae421d0e1c64874eaf2222e6b83614a09f3f859ff914acadad12bdd
platform-python-devel-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: ab2138c88234027d88fe57762cd12adc54121c5e9742e7d683053450aa246297
python3-debuginfo-3.6.8-39.el8_4.9.i686.rpm SHA-256: a25978e634e6678d109106e6c0c5a37cccebf4e3c9d7ddd9fbb140b0a282a073
python3-debuginfo-3.6.8-39.el8_4.9.i686.rpm SHA-256: a25978e634e6678d109106e6c0c5a37cccebf4e3c9d7ddd9fbb140b0a282a073
python3-debuginfo-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 6d451e11760aeb5f63df8762b4b6f28ff5e790f9334ca605547a7e97d999636e
python3-debuginfo-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 6d451e11760aeb5f63df8762b4b6f28ff5e790f9334ca605547a7e97d999636e
python3-debugsource-3.6.8-39.el8_4.9.i686.rpm SHA-256: ae2deb1f12b1de69494836dcc14018e32fe139d41d19e9784fa78319ae1815b0
python3-debugsource-3.6.8-39.el8_4.9.i686.rpm SHA-256: ae2deb1f12b1de69494836dcc14018e32fe139d41d19e9784fa78319ae1815b0
python3-debugsource-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 464cbdbce70be4a4ea5c05416c203defcd8ed1c240886c3b5917ad1ffad97632
python3-debugsource-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 464cbdbce70be4a4ea5c05416c203defcd8ed1c240886c3b5917ad1ffad97632
python3-idle-3.6.8-39.el8_4.9.i686.rpm SHA-256: eae710aa9d732ff55159ef527aa12af7e5ab7a5b13a30ce62d15d8544488be24
python3-idle-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: d8cda928d336e311ed915f56c219d5a8b3cecc3ab64f9b9a0d9a58422d28a4a1
python3-libs-3.6.8-39.el8_4.9.i686.rpm SHA-256: aabd3e69b77284f440e2dfa77bfa40cb32ab8f2e18d829099ec85c55798ddaa0
python3-libs-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: bfb8eca55bab36ebfe012c06eb95c1412bf0dd4e92c8380196061db2d58c9e67
python3-test-3.6.8-39.el8_4.9.i686.rpm SHA-256: 803340617eb7d0084948d94422dbc50af9db977b0d61f44e581be8aa406f6123
python3-test-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 425881b7920e1e8998faf079d9b88a546b5f1f8df358a4df28952412233ad103
python3-tkinter-3.6.8-39.el8_4.9.i686.rpm SHA-256: abb1013d7f86e564c89f17545fe952b4f7f52604cc93f9ff8d3574f384ebb27f
python3-tkinter-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 3d4622051063658224601d0ffd71ce2cc824b0aa102863428c8975a6d605121c

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
python3-3.6.8-39.el8_4.9.src.rpm SHA-256: e4269087e71655b6a43539a0def76bbe019709ff68d4f01985f3ff7b4499d153
x86_64
platform-python-3.6.8-39.el8_4.9.i686.rpm SHA-256: b4328a08a028cbe8ee2d2dc703c086300a1e6498d39693b8990d8e9d01bc636e
platform-python-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 776d0203ffa20a528ed6254760483dd5b144f9af92702f02e2b3e2b5d381de27
platform-python-debug-3.6.8-39.el8_4.9.i686.rpm SHA-256: 6d01625b4355ec183e32a6f04a81853e62bc730996cb5f27dbf8ec4f8cffa5cb
platform-python-debug-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 503641026ed29ab56ddf8dc6d94834d1ae4281e3a9a4d09baa1abdd8e2ad54c7
platform-python-devel-3.6.8-39.el8_4.9.i686.rpm SHA-256: e2984b7e1ae421d0e1c64874eaf2222e6b83614a09f3f859ff914acadad12bdd
platform-python-devel-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: ab2138c88234027d88fe57762cd12adc54121c5e9742e7d683053450aa246297
python3-debuginfo-3.6.8-39.el8_4.9.i686.rpm SHA-256: a25978e634e6678d109106e6c0c5a37cccebf4e3c9d7ddd9fbb140b0a282a073
python3-debuginfo-3.6.8-39.el8_4.9.i686.rpm SHA-256: a25978e634e6678d109106e6c0c5a37cccebf4e3c9d7ddd9fbb140b0a282a073
python3-debuginfo-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 6d451e11760aeb5f63df8762b4b6f28ff5e790f9334ca605547a7e97d999636e
python3-debuginfo-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 6d451e11760aeb5f63df8762b4b6f28ff5e790f9334ca605547a7e97d999636e
python3-debugsource-3.6.8-39.el8_4.9.i686.rpm SHA-256: ae2deb1f12b1de69494836dcc14018e32fe139d41d19e9784fa78319ae1815b0
python3-debugsource-3.6.8-39.el8_4.9.i686.rpm SHA-256: ae2deb1f12b1de69494836dcc14018e32fe139d41d19e9784fa78319ae1815b0
python3-debugsource-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 464cbdbce70be4a4ea5c05416c203defcd8ed1c240886c3b5917ad1ffad97632
python3-debugsource-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 464cbdbce70be4a4ea5c05416c203defcd8ed1c240886c3b5917ad1ffad97632
python3-idle-3.6.8-39.el8_4.9.i686.rpm SHA-256: eae710aa9d732ff55159ef527aa12af7e5ab7a5b13a30ce62d15d8544488be24
python3-idle-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: d8cda928d336e311ed915f56c219d5a8b3cecc3ab64f9b9a0d9a58422d28a4a1
python3-libs-3.6.8-39.el8_4.9.i686.rpm SHA-256: aabd3e69b77284f440e2dfa77bfa40cb32ab8f2e18d829099ec85c55798ddaa0
python3-libs-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: bfb8eca55bab36ebfe012c06eb95c1412bf0dd4e92c8380196061db2d58c9e67
python3-test-3.6.8-39.el8_4.9.i686.rpm SHA-256: 803340617eb7d0084948d94422dbc50af9db977b0d61f44e581be8aa406f6123
python3-test-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 425881b7920e1e8998faf079d9b88a546b5f1f8df358a4df28952412233ad103
python3-tkinter-3.6.8-39.el8_4.9.i686.rpm SHA-256: abb1013d7f86e564c89f17545fe952b4f7f52604cc93f9ff8d3574f384ebb27f
python3-tkinter-3.6.8-39.el8_4.9.x86_64.rpm SHA-256: 3d4622051063658224601d0ffd71ce2cc824b0aa102863428c8975a6d605121c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility