Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6464 - Security Advisory
Issued:
2026-04-02
Updated:
2026-04-02

RHSA-2026:6464 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: python3 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
  • cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)
  • cpython: email header injection due to unquoted newlines (CVE-2026-1299)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2431368 - CVE-2025-15366 cpython: IMAP command injection in user-controlled commands
  • BZ - 2431373 - CVE-2025-15367 cpython: POP3 command injection in user-controlled commands
  • BZ - 2432437 - CVE-2026-1299 cpython: email header injection due to unquoted newlines

CVEs

  • CVE-2025-15366
  • CVE-2025-15367
  • CVE-2026-1299

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
python3-3.6.8-21.el7_9.4.src.rpm SHA-256: 51fa9f3bfc005b3534f7f524d4c4b2f9d423fc70ff2e8549bf67f5d6e4c602ac
x86_64
python3-3.6.8-21.el7_9.4.i686.rpm SHA-256: 5be3194fb2fbed5cb5ee9755ab3f46e902b6f7fd0d03afb9744ab4b519cd29f1
python3-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: f1e90b6f23d0d88332557a96d8c319d3b596463dd8c8de9b00db32ff7392d36f
python3-debug-3.6.8-21.el7_9.4.i686.rpm SHA-256: da242467114d38c0c267c2d807a71f6220f986615ebfba02d692d09f00a68866
python3-debug-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: 0483e9f7a078f5991a5bc0dc566b0a32b40334d9f9361dad1b73cd6e2e6b3ecf
python3-debuginfo-3.6.8-21.el7_9.4.i686.rpm SHA-256: c6c4819a63907cbcb323de554b4b3fc62e3ab3bc869df99231d6b56e8defd80c
python3-debuginfo-3.6.8-21.el7_9.4.i686.rpm SHA-256: c6c4819a63907cbcb323de554b4b3fc62e3ab3bc869df99231d6b56e8defd80c
python3-debuginfo-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: c620948d9f509262aa258aee544f2c3813132d32d45e9f12f02c9507c417aac6
python3-debuginfo-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: c620948d9f509262aa258aee544f2c3813132d32d45e9f12f02c9507c417aac6
python3-devel-3.6.8-21.el7_9.4.i686.rpm SHA-256: 7b2bea6eb025604d52e379cafa72e8ecf5e813b12c2eb90886400e32c80dfe8a
python3-devel-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: 496d3fa7c7128974f53879f5a0d4fe4ba1a03ce3ef13fc69dda704bc5c57948b
python3-idle-3.6.8-21.el7_9.4.i686.rpm SHA-256: e8173ec250b747e4697764cff25bb7e6440b5c316ab67e2fc55bb7f46a47b743
python3-idle-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: 4c8f1d98301cc765a48afb0a0386e35a3fc116e6f65e50c73b4c0cd2c9a52709
python3-libs-3.6.8-21.el7_9.4.i686.rpm SHA-256: 8671f3964063f35ecf3d751d214e134bb406ca8ae82fddeb1839d53eab516601
python3-libs-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: 387be75ef52a877c6a036ef7a41dd0cccd3c7062868b6339bfe1f6ba3e1d86e9
python3-test-3.6.8-21.el7_9.4.i686.rpm SHA-256: 6b15ff4ac5933c84b2e09b6bc958f518e24c05f917f6b57ee1b077e6bc47c5d8
python3-test-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: 1f36b4eac7ab59386e04a9cda76201fc64fa77b8074d7587d2e8051c73db8ca1
python3-tkinter-3.6.8-21.el7_9.4.i686.rpm SHA-256: bf89e7b689384f8a968765776ee6100ae814fa798b1a4901b41cefd46bd5f967
python3-tkinter-3.6.8-21.el7_9.4.x86_64.rpm SHA-256: 0f50621362931a5984b3a78e604c3f91e55cb1eaa91eed7bb13fce99e7f4b13a

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
python3-3.6.8-21.el7_9.4.src.rpm SHA-256: 51fa9f3bfc005b3534f7f524d4c4b2f9d423fc70ff2e8549bf67f5d6e4c602ac
s390x
python3-3.6.8-21.el7_9.4.s390.rpm SHA-256: 4633e8f7fb1edb3e7e811ab1df19db45217ef27d7b1ffbfb4f0e2a009294197d
python3-3.6.8-21.el7_9.4.s390x.rpm SHA-256: 2f18beaa28a4c432ad9d84e20904d8a3e5ca09a145b052b6097eeecc0860305a
python3-debug-3.6.8-21.el7_9.4.s390.rpm SHA-256: 9aa28daf0341ff27ded90f6826eb748a1e9a7a80ec2328503620a30ceef078f1
python3-debug-3.6.8-21.el7_9.4.s390x.rpm SHA-256: 6e15e8a1e1e43a86b23b36a0b76b3e5b0e40419c332ebdadb55f79aace0145d8
python3-debuginfo-3.6.8-21.el7_9.4.s390.rpm SHA-256: eb4db4f5e0c1f05f32142f4617b8a1afbfdecacfdac2bc0a862d2a5ccc81128a
python3-debuginfo-3.6.8-21.el7_9.4.s390.rpm SHA-256: eb4db4f5e0c1f05f32142f4617b8a1afbfdecacfdac2bc0a862d2a5ccc81128a
python3-debuginfo-3.6.8-21.el7_9.4.s390x.rpm SHA-256: 92c989f86c57bfb0c43df3440595288ed23d1b2648d374529f109307112c039f
python3-debuginfo-3.6.8-21.el7_9.4.s390x.rpm SHA-256: 92c989f86c57bfb0c43df3440595288ed23d1b2648d374529f109307112c039f
python3-devel-3.6.8-21.el7_9.4.s390.rpm SHA-256: 272b56cd30063c8e98609215fb10b16d3966aefd461e42caa807fd9d98f6cb2c
python3-devel-3.6.8-21.el7_9.4.s390x.rpm SHA-256: 0551587eaf4c5e6b4a29d0bf9729004af182d60dc1132a9a7d75edaff151fc3d
python3-idle-3.6.8-21.el7_9.4.s390.rpm SHA-256: 9ce8564398b84c6708009b15dea29832812056f851d3ab8f1de7609141a89e84
python3-idle-3.6.8-21.el7_9.4.s390x.rpm SHA-256: b2940130afc92d0a059de0f097a3476824f1c6d092064a386770e84999a681e3
python3-libs-3.6.8-21.el7_9.4.s390.rpm SHA-256: 647be2ece55702e5b7313c65da2f460980729a706a65b0505dd5f5d9462f7cee
python3-libs-3.6.8-21.el7_9.4.s390x.rpm SHA-256: 211c6cf1db81a792c98542cece5b5270c2026a75a89b7e949a90b0a835cdc9df
python3-test-3.6.8-21.el7_9.4.s390.rpm SHA-256: d47170ef153939e05ea6ac9ffd4a797c32edd85d8aef9227d6062f8e945d6cb7
python3-test-3.6.8-21.el7_9.4.s390x.rpm SHA-256: 2556cebcb2e3126256f92421b4217caf64fbfd394f38580818aaa724a88d8275
python3-tkinter-3.6.8-21.el7_9.4.s390.rpm SHA-256: 1ab206433ab909a06f2c6260bcab6863dc386b61764ebaace248aeaaf8f41d6c
python3-tkinter-3.6.8-21.el7_9.4.s390x.rpm SHA-256: df61a18519dcd1f8c7a8544148a7accbcc1ef90e24dd0847709e212ec329f1e5

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
python3-3.6.8-21.el7_9.4.src.rpm SHA-256: 51fa9f3bfc005b3534f7f524d4c4b2f9d423fc70ff2e8549bf67f5d6e4c602ac
ppc64
python3-3.6.8-21.el7_9.4.ppc.rpm SHA-256: 9165e219c8414756eff53c364ebd7922976ce77091818b8bd29665fbe439cccc
python3-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: 56835e69caf7b9496278af4902a3a807030c664aa1e21850adc0f01017fd8387
python3-debug-3.6.8-21.el7_9.4.ppc.rpm SHA-256: b50cd529640ce33271403138c9de7c80478b33a6780d4158b6a18051e2765ede
python3-debug-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: d21e85fe489ca6c785f2e3020930b748f0b76ff97cde289339481436f70131b4
python3-debuginfo-3.6.8-21.el7_9.4.ppc.rpm SHA-256: e6ce4a5cd94f7e9ed64529b9f619e7cf80cdd9025ff5df7d5cb872a365e59973
python3-debuginfo-3.6.8-21.el7_9.4.ppc.rpm SHA-256: e6ce4a5cd94f7e9ed64529b9f619e7cf80cdd9025ff5df7d5cb872a365e59973
python3-debuginfo-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: 0b32934eb049fb5c571e28fcd62061ca24820086007a2556f9cc68feba281658
python3-debuginfo-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: 0b32934eb049fb5c571e28fcd62061ca24820086007a2556f9cc68feba281658
python3-devel-3.6.8-21.el7_9.4.ppc.rpm SHA-256: d1565dae1e24300c615649c21b56e8fcb7733c56122c0543b2b36146436fe09e
python3-devel-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: 74ab13ba69509ae841975577a8debc4db2c06fda5083cff36c1e1aabf8d5a27a
python3-idle-3.6.8-21.el7_9.4.ppc.rpm SHA-256: c185352a33d1ac4f66a432f6c375abb16b1d1e31708c2dc5f2611597763d6900
python3-idle-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: 6a8128bd27c13c6b1a4dfbda1488eca47b0d2d03d73a1c9ea300871f2398bddd
python3-libs-3.6.8-21.el7_9.4.ppc.rpm SHA-256: 684290dcfbdedf324b346aa7611242aae7179a66414c936791cfd0d6edc5ecf1
python3-libs-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: 53b07cc76dee9a66b3da09ccc7e714fbcc7cf8a7d88ae88a1e4ff26198b0e80d
python3-test-3.6.8-21.el7_9.4.ppc.rpm SHA-256: f0a8271fa56b800b00d4be9c86ccfe0989806fdfb3a611fa1a5fd01f4c118b05
python3-test-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: 7fdb201d87e488c06cc88e2acae4370b92118c8ecec647a294822d6ef872322d
python3-tkinter-3.6.8-21.el7_9.4.ppc.rpm SHA-256: ddd87d932719cebabb267e69e63ac7e3724ec07178835bb82fcc8405ae8250a9
python3-tkinter-3.6.8-21.el7_9.4.ppc64.rpm SHA-256: c2b9c0c4b0f8f0798a49d1b556f2361a3759ce037669420bfa3c0fbe9aa08708

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
python3-3.6.8-21.el7_9.4.src.rpm SHA-256: 51fa9f3bfc005b3534f7f524d4c4b2f9d423fc70ff2e8549bf67f5d6e4c602ac
ppc64le
python3-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: 8a9b273e0b2fc9f93bcb8356956168c6347c95efbe90c58e020d568dd59c61cf
python3-debug-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: 9243da81b65f4d8abb6e8cefdcb59945c90a1945f35d08498209b9bb8603d55a
python3-debuginfo-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: e707877c4789cf2e179cd4e2a51095055d76e3ac20ff76eeb67709eaa15faef6
python3-debuginfo-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: e707877c4789cf2e179cd4e2a51095055d76e3ac20ff76eeb67709eaa15faef6
python3-devel-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: 09c070b7388febaba2a73acd96699eed769e42160db5a83be4fe7ccac65085c1
python3-idle-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: 6104777ef4a793eda7628a96dcae33affb4f9adf31f8e1125f5bf62892dc89ec
python3-libs-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: 638f80d3e2ac10acc787e19e0dd2ab13c97581a23b107a7944fbac8740143d51
python3-test-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: 8c7623053c00ecbe1883be9c277ec1bbf50e336c72ddd3d056ba95dbeddac33e
python3-tkinter-3.6.8-21.el7_9.4.ppc64le.rpm SHA-256: 0a665c08c5dedea51b047200e3ce911084d157bcd4427c7e5e08801725764aa2

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility