Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5223 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5223 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: python3.11 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3.11 is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
  • cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)
  • cpython: email header injection due to unquoted newlines (CVE-2026-1299)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x

Fixes

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
  • BZ - 2432437 - CVE-2026-1299 cpython: email header injection due to unquoted newlines

CVEs

  • CVE-2025-15366
  • CVE-2025-15367
  • CVE-2026-1299

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
x86_64
python3.11-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: a007d375476f8e2fe8a758e8c67dbe97886713090b22c98e615bbfdb0ea9edcf
python3.11-debuginfo-3.11.2-2.el9_2.10.i686.rpm SHA-256: 367b72201c29f510d17c22d3a819ab6022bc7fe258002e6dc3268a4b35b13a3e
python3.11-debuginfo-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: ba798775e08ce5caf2b2b2844a0dbb2774b458c1a39eaf5f8de99680397fc9d4
python3.11-debugsource-3.11.2-2.el9_2.10.i686.rpm SHA-256: 4ac8f90cb764a68f3cef0548282f48790ba53bbad760ec43c33c1448705a3eb9
python3.11-debugsource-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: 9ea4c008af4fa6821dda2211fa712a5e2f83ac0282b464d54b07aa21142869ea
python3.11-devel-3.11.2-2.el9_2.10.i686.rpm SHA-256: 4ba05ccb5a99fa507e6f61188decc6a1a03b9adc61ee69f7f5e9acdc18626324
python3.11-devel-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: 5a1c5bafba77ad2d52fe8fec94ad2bc2fa12365bcfc972835a5dcedb05992a6e
python3.11-libs-3.11.2-2.el9_2.10.i686.rpm SHA-256: 6f2c42072942f8f2062da31c087e6498e4387be0c1cdb12276f535342d00e352
python3.11-libs-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: f503251effc6bf58d70ac831960124a4e97b5638e2ced3787286b2aca78b1410
python3.11-tkinter-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: fe42f55b6bc56e9ff5423ddcdf8dcdba13669a0c202d92365b905e8f414323bd

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
ppc64le
python3.11-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 2aff7fa46726a4acb0324dcd9992d4e23b376c9257c651334f6e6a5a16456b6d
python3.11-debuginfo-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 3b89e55051a2d3c416d58af41db581254db4e87bf7b78ed97ddb070ec77cb2d8
python3.11-debugsource-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 1eecf687ebb8b1bf7ad38933c41a30541310d268be1a90baf8c0c79f11437075
python3.11-devel-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: b9e5aadf7758aac618bc0fe2edaab975d250a87f27105fdaf4964c32442dd6eb
python3.11-libs-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 53f0cacbabffc963e2a5892760b7e62835456327c45c68265f6df14bc8e66f49
python3.11-tkinter-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: e3b51f5f0658c9fe055d24713fef252145f8374fd38f6303d8effc0ff6891a31

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
x86_64
python3.11-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: a007d375476f8e2fe8a758e8c67dbe97886713090b22c98e615bbfdb0ea9edcf
python3.11-debuginfo-3.11.2-2.el9_2.10.i686.rpm SHA-256: 367b72201c29f510d17c22d3a819ab6022bc7fe258002e6dc3268a4b35b13a3e
python3.11-debuginfo-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: ba798775e08ce5caf2b2b2844a0dbb2774b458c1a39eaf5f8de99680397fc9d4
python3.11-debugsource-3.11.2-2.el9_2.10.i686.rpm SHA-256: 4ac8f90cb764a68f3cef0548282f48790ba53bbad760ec43c33c1448705a3eb9
python3.11-debugsource-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: 9ea4c008af4fa6821dda2211fa712a5e2f83ac0282b464d54b07aa21142869ea
python3.11-devel-3.11.2-2.el9_2.10.i686.rpm SHA-256: 4ba05ccb5a99fa507e6f61188decc6a1a03b9adc61ee69f7f5e9acdc18626324
python3.11-devel-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: 5a1c5bafba77ad2d52fe8fec94ad2bc2fa12365bcfc972835a5dcedb05992a6e
python3.11-libs-3.11.2-2.el9_2.10.i686.rpm SHA-256: 6f2c42072942f8f2062da31c087e6498e4387be0c1cdb12276f535342d00e352
python3.11-libs-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: f503251effc6bf58d70ac831960124a4e97b5638e2ced3787286b2aca78b1410
python3.11-tkinter-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: fe42f55b6bc56e9ff5423ddcdf8dcdba13669a0c202d92365b905e8f414323bd

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
aarch64
python3.11-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 1f9abafc768b82b4da7b5ec138bdc8298006bfc3c51204a14878533807d7daff
python3.11-debuginfo-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 149ae0738e75d386d8bccbf38d5d542df6eee98205bc8908838ebe6f33ea8a22
python3.11-debugsource-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 917af11912e44414183b032386b6ffbbec5360b14c13abfe4b2479feb631a1ee
python3.11-devel-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 7e707d69f1549bd5d8bc3e8f89fe14f8acdb5917866899414616ab3420808b0c
python3.11-libs-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: bec8d02076ceaf2d8855d2dbcb4fd0ac70e3db7adbbd5b7437478077a0e280d4
python3.11-tkinter-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: e3840a9c39b88ad0d9f3056d7e3788609795e334f742e8bb6e9c605243c2b601

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
s390x
python3.11-3.11.2-2.el9_2.10.s390x.rpm SHA-256: 19187925ab16bf38da664a3ac61ccb41ef815d72eb46d64c42ef41528dfd2680
python3.11-debuginfo-3.11.2-2.el9_2.10.s390x.rpm SHA-256: ec7a9b60f5049e3c5544ad1550355bf1b05560beb6e2ca6220f5e918d24de7dd
python3.11-debugsource-3.11.2-2.el9_2.10.s390x.rpm SHA-256: 44eb1ff14632a97e029397d1533268a05b7aa887e1e64f395cf245b68f3fa6b8
python3.11-devel-3.11.2-2.el9_2.10.s390x.rpm SHA-256: f19bccc5ab2665ecdc9383a08cb591903a7577bb0de04d759c425db21e999120
python3.11-libs-3.11.2-2.el9_2.10.s390x.rpm SHA-256: d1b10a13b2a2ecc05edb748e876796faf0b6ada6d52539ab0606a0df562f34b5
python3.11-tkinter-3.11.2-2.el9_2.10.s390x.rpm SHA-256: 65600a984d25700f512960db4894706dd4b6260456fe95e5c94fbc9b21e6ccda

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
x86_64
python3.11-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: a007d375476f8e2fe8a758e8c67dbe97886713090b22c98e615bbfdb0ea9edcf
python3.11-debuginfo-3.11.2-2.el9_2.10.i686.rpm SHA-256: 367b72201c29f510d17c22d3a819ab6022bc7fe258002e6dc3268a4b35b13a3e
python3.11-debuginfo-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: ba798775e08ce5caf2b2b2844a0dbb2774b458c1a39eaf5f8de99680397fc9d4
python3.11-debugsource-3.11.2-2.el9_2.10.i686.rpm SHA-256: 4ac8f90cb764a68f3cef0548282f48790ba53bbad760ec43c33c1448705a3eb9
python3.11-debugsource-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: 9ea4c008af4fa6821dda2211fa712a5e2f83ac0282b464d54b07aa21142869ea
python3.11-devel-3.11.2-2.el9_2.10.i686.rpm SHA-256: 4ba05ccb5a99fa507e6f61188decc6a1a03b9adc61ee69f7f5e9acdc18626324
python3.11-devel-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: 5a1c5bafba77ad2d52fe8fec94ad2bc2fa12365bcfc972835a5dcedb05992a6e
python3.11-libs-3.11.2-2.el9_2.10.i686.rpm SHA-256: 6f2c42072942f8f2062da31c087e6498e4387be0c1cdb12276f535342d00e352
python3.11-libs-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: f503251effc6bf58d70ac831960124a4e97b5638e2ced3787286b2aca78b1410
python3.11-tkinter-3.11.2-2.el9_2.10.x86_64.rpm SHA-256: fe42f55b6bc56e9ff5423ddcdf8dcdba13669a0c202d92365b905e8f414323bd

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
aarch64
python3.11-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 1f9abafc768b82b4da7b5ec138bdc8298006bfc3c51204a14878533807d7daff
python3.11-debuginfo-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 149ae0738e75d386d8bccbf38d5d542df6eee98205bc8908838ebe6f33ea8a22
python3.11-debugsource-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 917af11912e44414183b032386b6ffbbec5360b14c13abfe4b2479feb631a1ee
python3.11-devel-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: 7e707d69f1549bd5d8bc3e8f89fe14f8acdb5917866899414616ab3420808b0c
python3.11-libs-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: bec8d02076ceaf2d8855d2dbcb4fd0ac70e3db7adbbd5b7437478077a0e280d4
python3.11-tkinter-3.11.2-2.el9_2.10.aarch64.rpm SHA-256: e3840a9c39b88ad0d9f3056d7e3788609795e334f742e8bb6e9c605243c2b601

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
ppc64le
python3.11-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 2aff7fa46726a4acb0324dcd9992d4e23b376c9257c651334f6e6a5a16456b6d
python3.11-debuginfo-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 3b89e55051a2d3c416d58af41db581254db4e87bf7b78ed97ddb070ec77cb2d8
python3.11-debugsource-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 1eecf687ebb8b1bf7ad38933c41a30541310d268be1a90baf8c0c79f11437075
python3.11-devel-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: b9e5aadf7758aac618bc0fe2edaab975d250a87f27105fdaf4964c32442dd6eb
python3.11-libs-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: 53f0cacbabffc963e2a5892760b7e62835456327c45c68265f6df14bc8e66f49
python3.11-tkinter-3.11.2-2.el9_2.10.ppc64le.rpm SHA-256: e3b51f5f0658c9fe055d24713fef252145f8374fd38f6303d8effc0ff6891a31

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.10.src.rpm SHA-256: aa5fbf2937d0a42a36da1aaa94f246ededa954b1b0cd64b41a2803877d0dd67b
s390x
python3.11-3.11.2-2.el9_2.10.s390x.rpm SHA-256: 19187925ab16bf38da664a3ac61ccb41ef815d72eb46d64c42ef41528dfd2680
python3.11-debuginfo-3.11.2-2.el9_2.10.s390x.rpm SHA-256: ec7a9b60f5049e3c5544ad1550355bf1b05560beb6e2ca6220f5e918d24de7dd
python3.11-debugsource-3.11.2-2.el9_2.10.s390x.rpm SHA-256: 44eb1ff14632a97e029397d1533268a05b7aa887e1e64f395cf245b68f3fa6b8
python3.11-devel-3.11.2-2.el9_2.10.s390x.rpm SHA-256: f19bccc5ab2665ecdc9383a08cb591903a7577bb0de04d759c425db21e999120
python3.11-libs-3.11.2-2.el9_2.10.s390x.rpm SHA-256: d1b10a13b2a2ecc05edb748e876796faf0b6ada6d52539ab0606a0df562f34b5
python3.11-tkinter-3.11.2-2.el9_2.10.s390x.rpm SHA-256: 65600a984d25700f512960db4894706dd4b6260456fe95e5c94fbc9b21e6ccda

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility