Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5225 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5225 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: python3.9 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3.9 is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
  • cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)
  • cpython: email header injection due to unquoted newlines (CVE-2026-1299)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
  • BZ - 2432437 - CVE-2026-1299 cpython: email header injection due to unquoted newlines

CVEs

  • CVE-2025-15366
  • CVE-2025-15367
  • CVE-2026-1299

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
python3.9-3.9.16-1.el9_2.12.src.rpm SHA-256: 4c68e8683ec74c72d2e3bfd54a5bf13db6129de79bb73001b3012bd04f9d3ca7
x86_64
python-unversioned-command-3.9.16-1.el9_2.12.noarch.rpm SHA-256: a7b4b8719fbded3bf35461ea347460a0b43b0ca5d3ad5d6df8ebc9684cff3564
python3-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 74fd43f2905ee2c6d1e5834283256c558648bad5f3517dbf4a9f1cc9b50cf07c
python3-devel-3.9.16-1.el9_2.12.i686.rpm SHA-256: c5c3e8e1c9397e8091da42852ce5e37108aba88181ad14ddb5538ca29a7ded68
python3-devel-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 9fc98d350ec0e63f077eb5b3b3732ee2a5b4ba6a060b8452a9a8d91b49c578dd
python3-libs-3.9.16-1.el9_2.12.i686.rpm SHA-256: 432f2c536ab896e3a2e3c36a354350591ebeec79fd613df2de7f7cd87c28f608
python3-libs-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 1c96b572e59ff64b733cfe0e79794029128af2dcc8146e58a446aab2257649af
python3-tkinter-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 6660d166ed10e5d4dffb119e492226e5bbf592e39054330798d8024369f19b4a
python3.9-debuginfo-3.9.16-1.el9_2.12.i686.rpm SHA-256: be4f7fe6f4c8216a4a61709695c1a7e57ee020cc89b402d9e422e678862dd88d
python3.9-debuginfo-3.9.16-1.el9_2.12.i686.rpm SHA-256: be4f7fe6f4c8216a4a61709695c1a7e57ee020cc89b402d9e422e678862dd88d
python3.9-debuginfo-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 487a3c3fbd522d4caf1e93d3c5ccdcd4f63df62b4268f6c38fa5d2731c402964
python3.9-debuginfo-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 487a3c3fbd522d4caf1e93d3c5ccdcd4f63df62b4268f6c38fa5d2731c402964
python3.9-debugsource-3.9.16-1.el9_2.12.i686.rpm SHA-256: 9b03d890e877d69ae0c72baf8e43619d34fa3795f38b477197c528ce998cf966
python3.9-debugsource-3.9.16-1.el9_2.12.i686.rpm SHA-256: 9b03d890e877d69ae0c72baf8e43619d34fa3795f38b477197c528ce998cf966
python3.9-debugsource-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 215fb8b83b7063b01370a76a8364d9a5f599fa744fc77ab504d67f9d0cef468e
python3.9-debugsource-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 215fb8b83b7063b01370a76a8364d9a5f599fa744fc77ab504d67f9d0cef468e

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
python3.9-3.9.16-1.el9_2.12.src.rpm SHA-256: 4c68e8683ec74c72d2e3bfd54a5bf13db6129de79bb73001b3012bd04f9d3ca7
ppc64le
python-unversioned-command-3.9.16-1.el9_2.12.noarch.rpm SHA-256: a7b4b8719fbded3bf35461ea347460a0b43b0ca5d3ad5d6df8ebc9684cff3564
python3-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: b6b13ccbef122e4bc65aa132e59a9bf0cb989789b1b4a1315172403128e15024
python3-devel-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: 734f15283722a5d7503cb367b57c70d0f3d510cbefe6ff795e1f0c6e85b9d74a
python3-libs-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: 05d342478a288935bf2ba1cb511cd56e83aa6c08347608bafca15c4a10cf4710
python3-tkinter-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: 2bbdb5588772e3b3d9e48cfc4fc2615330ab30ecf3b28cd1cb242459259eb777
python3.9-debuginfo-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: d605066a88ec7b2346b5b3527eee0aaf092a7c5aeaf8c7f3486dfa43225bf15e
python3.9-debuginfo-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: d605066a88ec7b2346b5b3527eee0aaf092a7c5aeaf8c7f3486dfa43225bf15e
python3.9-debugsource-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: e1e2224ba3bee7481ffca0530373d63ff0aea20fdeb750bcaa33507d099e9e4d
python3.9-debugsource-3.9.16-1.el9_2.12.ppc64le.rpm SHA-256: e1e2224ba3bee7481ffca0530373d63ff0aea20fdeb750bcaa33507d099e9e4d

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
python3.9-3.9.16-1.el9_2.12.src.rpm SHA-256: 4c68e8683ec74c72d2e3bfd54a5bf13db6129de79bb73001b3012bd04f9d3ca7
x86_64
python-unversioned-command-3.9.16-1.el9_2.12.noarch.rpm SHA-256: a7b4b8719fbded3bf35461ea347460a0b43b0ca5d3ad5d6df8ebc9684cff3564
python3-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 74fd43f2905ee2c6d1e5834283256c558648bad5f3517dbf4a9f1cc9b50cf07c
python3-devel-3.9.16-1.el9_2.12.i686.rpm SHA-256: c5c3e8e1c9397e8091da42852ce5e37108aba88181ad14ddb5538ca29a7ded68
python3-devel-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 9fc98d350ec0e63f077eb5b3b3732ee2a5b4ba6a060b8452a9a8d91b49c578dd
python3-libs-3.9.16-1.el9_2.12.i686.rpm SHA-256: 432f2c536ab896e3a2e3c36a354350591ebeec79fd613df2de7f7cd87c28f608
python3-libs-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 1c96b572e59ff64b733cfe0e79794029128af2dcc8146e58a446aab2257649af
python3-tkinter-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 6660d166ed10e5d4dffb119e492226e5bbf592e39054330798d8024369f19b4a
python3.9-debuginfo-3.9.16-1.el9_2.12.i686.rpm SHA-256: be4f7fe6f4c8216a4a61709695c1a7e57ee020cc89b402d9e422e678862dd88d
python3.9-debuginfo-3.9.16-1.el9_2.12.i686.rpm SHA-256: be4f7fe6f4c8216a4a61709695c1a7e57ee020cc89b402d9e422e678862dd88d
python3.9-debuginfo-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 487a3c3fbd522d4caf1e93d3c5ccdcd4f63df62b4268f6c38fa5d2731c402964
python3.9-debuginfo-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 487a3c3fbd522d4caf1e93d3c5ccdcd4f63df62b4268f6c38fa5d2731c402964
python3.9-debugsource-3.9.16-1.el9_2.12.i686.rpm SHA-256: 9b03d890e877d69ae0c72baf8e43619d34fa3795f38b477197c528ce998cf966
python3.9-debugsource-3.9.16-1.el9_2.12.i686.rpm SHA-256: 9b03d890e877d69ae0c72baf8e43619d34fa3795f38b477197c528ce998cf966
python3.9-debugsource-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 215fb8b83b7063b01370a76a8364d9a5f599fa744fc77ab504d67f9d0cef468e
python3.9-debugsource-3.9.16-1.el9_2.12.x86_64.rpm SHA-256: 215fb8b83b7063b01370a76a8364d9a5f599fa744fc77ab504d67f9d0cef468e

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
python3.9-3.9.16-1.el9_2.12.src.rpm SHA-256: 4c68e8683ec74c72d2e3bfd54a5bf13db6129de79bb73001b3012bd04f9d3ca7
aarch64
python-unversioned-command-3.9.16-1.el9_2.12.noarch.rpm SHA-256: a7b4b8719fbded3bf35461ea347460a0b43b0ca5d3ad5d6df8ebc9684cff3564
python3-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: 211d5a8cc70bc693b7c67ac30c3e43356b3a8079c380851087f5322d0f37d09a
python3-devel-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: 5f778b7a5e063b239474d2d85eb70844c997c4bf605e811aa1b0bb93226462f8
python3-libs-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: cdea034fc0785f54dfd519726a2def508d648c3c58557e7d97c1a5d5067b321b
python3-tkinter-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: f950b16367230f4b43aa99e9f1390d6b205edaa6b4097f38e3763d99ffd2facc
python3.9-debuginfo-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: d010457f7d38b20695ddd82ec94e51b67ed3ca9598f7504c32a994f4b56cdacc
python3.9-debuginfo-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: d010457f7d38b20695ddd82ec94e51b67ed3ca9598f7504c32a994f4b56cdacc
python3.9-debugsource-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: 8ea37c4498f87e45bb0c4b4f98bb09f7f4238e6553d61c28b796f53959e12169
python3.9-debugsource-3.9.16-1.el9_2.12.aarch64.rpm SHA-256: 8ea37c4498f87e45bb0c4b4f98bb09f7f4238e6553d61c28b796f53959e12169

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
python3.9-3.9.16-1.el9_2.12.src.rpm SHA-256: 4c68e8683ec74c72d2e3bfd54a5bf13db6129de79bb73001b3012bd04f9d3ca7
s390x
python-unversioned-command-3.9.16-1.el9_2.12.noarch.rpm SHA-256: a7b4b8719fbded3bf35461ea347460a0b43b0ca5d3ad5d6df8ebc9684cff3564
python3-3.9.16-1.el9_2.12.s390x.rpm SHA-256: dc0defb38a0f8ea215810452a672a88d24cffd7652290b3b6318125d240ec4ee
python3-devel-3.9.16-1.el9_2.12.s390x.rpm SHA-256: 94e0d17230119187f03ecae9ff31b77968afca3c6dfa4091aae497eeae1a912c
python3-libs-3.9.16-1.el9_2.12.s390x.rpm SHA-256: 7ebbda9d5f72db76bc568fdde0c3cffeedbd3a37350e0e1a89dc967a173475ab
python3-tkinter-3.9.16-1.el9_2.12.s390x.rpm SHA-256: 476472a9938a70693c4b1252481b4cece97c367f0b696cf0dcdb7dd761b3600c
python3.9-debuginfo-3.9.16-1.el9_2.12.s390x.rpm SHA-256: e1783d71ebbac7010bb3b6a4b6d895b7e8e4cd0b57a1b34930e970e5921a3c03
python3.9-debuginfo-3.9.16-1.el9_2.12.s390x.rpm SHA-256: e1783d71ebbac7010bb3b6a4b6d895b7e8e4cd0b57a1b34930e970e5921a3c03
python3.9-debugsource-3.9.16-1.el9_2.12.s390x.rpm SHA-256: 4238b6c64f8819b10f89ca133b4ebce69d39fb78c5f70019e09fb47ed3b95aea
python3.9-debugsource-3.9.16-1.el9_2.12.s390x.rpm SHA-256: 4238b6c64f8819b10f89ca133b4ebce69d39fb78c5f70019e09fb47ed3b95aea

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility