RHSA-2026:56219: Important: python3 security update
Important: python3 security update
Other sources
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.Security Fix(es): python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory (CVE-2026-11940) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python3to a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/platform-pythonto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/platform-python-debugto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/platform-python-develto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/python3-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/python3-debugsourceto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/python3-idleto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/python3-libsto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/python3-testto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/python3-tkinterto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10 - Upgrade
Upgrade
redhat/platform-pythonto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/platform-python-debugto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/platform-python-develto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/python3-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/python3-debugsourceto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/python3-idleto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/python3-libsto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/python3-testto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa - Upgrade
Upgrade
redhat/python3-tkinterto a version that resolves this vulnerability.Fixed in 3.6.8-78.el8_10.aa
Event History
Frequently Asked Questions
Which installed packages should be considered affected?
Systems with the listed Red Hat Python 3 or platform-python packages are in scope for this update, including runtime libraries, development packages, debug packages, IDLE, and test packages.
What attacker-controlled condition is relevant to exploitation?
Exploitation involves CPython tarfile extraction and a filter-bypass condition that can allow files to escape the intended destination directory. The advisory does not state whether a default configuration is affected or provide a temporary mitigation.
How can I prioritize systems while applying the update?
Review whether applications or administrative workflows extract untrusted tar archives using Python's tarfile functionality, particularly where extraction is expected to remain confined to a chosen directory. The supplied advisory data does not include affected or fixed package versions, so package update status must be checked against the Red Hat erratum.