Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5393 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5393 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: python security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
  • cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands

CVEs

  • CVE-2025-15366
  • CVE-2025-15367

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
python-2.7.5-94.el7_9.3.src.rpm SHA-256: 2ea10a87690fcfd69d0a8a3de819bed1d297d33a3c5d32709ff9559464de0bad
x86_64
python-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: 80aede596fbc906da7ce6a94b3f40cc9103614229ec7adf5f1e0e5ab79c8f375
python-debug-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: 4932d1d7b6c7c9ee21742c3a032da917be7c3cdcf20480fd557dcb97c7a0afdc
python-debuginfo-2.7.5-94.el7_9.3.i686.rpm SHA-256: 8e09db812996b46eeda99f71c147369e5dacac8fd3863a8c57dd6a4bb52afa3a
python-debuginfo-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: f233232a1d407595b941d65df5c6bc0593b14211e0011b21798509b6578141db
python-debuginfo-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: f233232a1d407595b941d65df5c6bc0593b14211e0011b21798509b6578141db
python-devel-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: 36793e840c9e047a686a8c3f011ff3aa533b3446fc61787768c9580dad569606
python-libs-2.7.5-94.el7_9.3.i686.rpm SHA-256: 06c88792cc3c045bb855f931627034f9ee38afb95c24bb3a84d90fb447665c67
python-libs-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: 56f884949db947fdda818075b45d63c7149654bea3a26641d9bdb02ddf677980
python-test-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: 0e6459dc5b6ab5324133caad6576c6a866e82fa93aeef32976e58d421a0c0de8
python-tools-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: e84f5c41a544b515c047e373b3bc80473072c29df73c86495f7555e52ce9b07d
tkinter-2.7.5-94.el7_9.3.x86_64.rpm SHA-256: 60505ad72a5a19591053ca0c5b1bd5ee6bd63ed848494e2a0aa867d87e9f1e0e

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
python-2.7.5-94.el7_9.3.src.rpm SHA-256: 2ea10a87690fcfd69d0a8a3de819bed1d297d33a3c5d32709ff9559464de0bad
s390x
python-2.7.5-94.el7_9.3.s390x.rpm SHA-256: aa82fd68ab6a264aacadb791425c009c70dc818870b41566bdb2a91a4bcf6f58
python-debug-2.7.5-94.el7_9.3.s390x.rpm SHA-256: b315a5346f85a9493987b2c7dcd9f61951b3571c36cc1d1add9c699d78507989
python-debuginfo-2.7.5-94.el7_9.3.s390.rpm SHA-256: 6a3f55e7ce124c0a00f098b27fa516976f817cd8fd28ee8f6720d5bd63922c72
python-debuginfo-2.7.5-94.el7_9.3.s390x.rpm SHA-256: 2e17b91462c4b27d86fc77ae7505d083b3bb1005486f0d10fcb4cf60936d79e8
python-debuginfo-2.7.5-94.el7_9.3.s390x.rpm SHA-256: 2e17b91462c4b27d86fc77ae7505d083b3bb1005486f0d10fcb4cf60936d79e8
python-devel-2.7.5-94.el7_9.3.s390x.rpm SHA-256: 3c45f717fe6a8b16332d8e6a474f00406a6c23e6a96683348a2cd39192b53df5
python-libs-2.7.5-94.el7_9.3.s390.rpm SHA-256: 564aeff04e45db5a71d9dc550863a214494f8c94ec8ebf0bd28bafbe36b981c3
python-libs-2.7.5-94.el7_9.3.s390x.rpm SHA-256: 6fdb60e43ff9a41ab3e69f48c5a99033cc7c638747675fb1f31253a6a75f6073
python-test-2.7.5-94.el7_9.3.s390x.rpm SHA-256: d02bc99c853cf3d86389e6601f861dafa50a2d7c7011f67431fec0794f049cd0
python-tools-2.7.5-94.el7_9.3.s390x.rpm SHA-256: 0e2085d31913d89e52f8275a0ca66a0f112c356f9186549bdda12c76f98db8b1
tkinter-2.7.5-94.el7_9.3.s390x.rpm SHA-256: fd36a7edf93344f54cfdffe90e03b241729cae32ed6a7c195dbdd2347228abac

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
python-2.7.5-94.el7_9.3.src.rpm SHA-256: 2ea10a87690fcfd69d0a8a3de819bed1d297d33a3c5d32709ff9559464de0bad
ppc64
python-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: 64205a055bb7dc4f7fc1dcb1cabc0c780ae974e2d5483b47fa02f784c6e1f136
python-debug-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: 2630ada39f8ec9b531d7f9d5e970fe0b5e6f91986a5d93a435b60560473f2a2c
python-debuginfo-2.7.5-94.el7_9.3.ppc.rpm SHA-256: d59e7e67cd44a2d27e47f10a69d6cbaa364b01d738ce2f1c16cb5798a01f2d0a
python-debuginfo-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: c664a0c202512dad9a064ef02786f5b3102a7500482312abc44b3a99d88af680
python-debuginfo-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: c664a0c202512dad9a064ef02786f5b3102a7500482312abc44b3a99d88af680
python-devel-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: 6bce42550a54faf3359620b5dedcee4ee0619ce7797afc44ee0cb477bfa6876f
python-libs-2.7.5-94.el7_9.3.ppc.rpm SHA-256: f8894704fa52ab86383f07a5ac49d6a1b5a7c6967e92a3c7286625d9e27faded
python-libs-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: 86e2bb2c7c7736c220248012a583bdb8f949ba9c3a2a48fa2bc61805982a95b5
python-test-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: f0b1f556df75c33b5c1ccaf151bf9a22246e23dab57d125d1749ae3453c1b2c0
python-tools-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: 4634cf817537513848ef1d445fdc5662d7323c151b0d4b0f9da556ab79eba3b8
tkinter-2.7.5-94.el7_9.3.ppc64.rpm SHA-256: b96e18ade08f101b6af85015faea2dd280152861a509020650c4860fc6b9dea1

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
python-2.7.5-94.el7_9.3.src.rpm SHA-256: 2ea10a87690fcfd69d0a8a3de819bed1d297d33a3c5d32709ff9559464de0bad
ppc64le
python-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: 2d978d8e06ea299c607b50046ec52022de92cf206ef67d2f961d4ada62051a6a
python-debug-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: 634955e96a77261085fa32ecd802d348a0f2c64f00d51723fa0394d94bbc0d1f
python-debuginfo-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: 146da8145ab974ff6f2abeb3d959c4d3b6cb2dc1d0af178d0aff7f69b5d25c4e
python-debuginfo-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: 146da8145ab974ff6f2abeb3d959c4d3b6cb2dc1d0af178d0aff7f69b5d25c4e
python-devel-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: 6c7828031a056338ba19b82448ba4a45474cde41957e189b471d75e62ab50185
python-libs-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: d1804bdd1597a3e52936d7c4b4827767a999a833ff13e3bf509c555bcf5f48f7
python-test-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: ad8069a1c1b53cf5729080b6f4863d35de936b0ffc4061e81f8467a7bce07cbd
python-tools-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: f682d84f98e092175ef72dbe10434d3c2bd6f2a6eccc7a9fcc301d52a4add857
tkinter-2.7.5-94.el7_9.3.ppc64le.rpm SHA-256: 44d8d5a89afcafebc9a0be1f3dccdde69197cca39fba424750982df8e076582a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility