Red Hat Security Advisory: python3.12 security update
A security update for python3.12 in Red Hat Enterprise Linux 9.4 addresses two vulnerabilities: a use-after-free in decompression modules (CVE-2026-6100) and a command injection in the webbrowser.open() API (CVE-2026-4786). Both vulnerabilities could lead to arbitrary code execution or information disclosure. Red Hat has released updated packages to fix these issues in multiple architectures and product variants. The update is rated as Important by Red Hat Product Security. No CVSS scores are provided in the advisory. No known exploits are reported in the wild at this time.
AI Analysis
Technical Summary
This advisory covers two security vulnerabilities in Python 3.12 as packaged by Red Hat for Enterprise Linux 9.4. CVE-2026-6100 is a use-after-free vulnerability in decompression modules that could allow arbitrary code execution or information disclosure. CVE-2026-4786 is a command injection vulnerability in the webbrowser.open() API that could lead to arbitrary code execution. Red Hat has issued updated python3.12 packages that address these issues across multiple supported architectures and variants of Red Hat Enterprise Linux 9.4. The advisory references Red Hat Bugzilla entries 2457932 and 2458049 for the respective CVEs and provides links to updated packages and remediation instructions. No CVSS scores are included, and no active exploitation is known.
Potential Impact
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code or cause information disclosure on affected systems running vulnerable versions of python3.12. The use-after-free in decompression modules (CVE-2026-6100) and command injection in the webbrowser.open() API (CVE-2026-4786) both pose significant security risks. However, no known exploits are currently reported in the wild. The vulnerabilities affect Red Hat Enterprise Linux 9.4 and related product variants using python3.12.
Mitigation Recommendations
Red Hat has released updated python3.12 packages that fix these vulnerabilities. Users should apply the security update for python3.12 as provided in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and other affected variants. Detailed update instructions are available at https://access.redhat.com/articles/11258. Applying these updates will remediate the vulnerabilities. No additional mitigation steps are indicated by the vendor advisory.
Red Hat Security Advisory: python3.12 security update
Description
A security update for python3.12 in Red Hat Enterprise Linux 9.4 addresses two vulnerabilities: a use-after-free in decompression modules (CVE-2026-6100) and a command injection in the webbrowser.open() API (CVE-2026-4786). Both vulnerabilities could lead to arbitrary code execution or information disclosure. Red Hat has released updated packages to fix these issues in multiple architectures and product variants. The update is rated as Important by Red Hat Product Security. No CVSS scores are provided in the advisory. No known exploits are reported in the wild at this time.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers two security vulnerabilities in Python 3.12 as packaged by Red Hat for Enterprise Linux 9.4. CVE-2026-6100 is a use-after-free vulnerability in decompression modules that could allow arbitrary code execution or information disclosure. CVE-2026-4786 is a command injection vulnerability in the webbrowser.open() API that could lead to arbitrary code execution. Red Hat has issued updated python3.12 packages that address these issues across multiple supported architectures and variants of Red Hat Enterprise Linux 9.4. The advisory references Red Hat Bugzilla entries 2457932 and 2458049 for the respective CVEs and provides links to updated packages and remediation instructions. No CVSS scores are included, and no active exploitation is known.
Potential Impact
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code or cause information disclosure on affected systems running vulnerable versions of python3.12. The use-after-free in decompression modules (CVE-2026-6100) and command injection in the webbrowser.open() API (CVE-2026-4786) both pose significant security risks. However, no known exploits are currently reported in the wild. The vulnerabilities affect Red Hat Enterprise Linux 9.4 and related product variants using python3.12.
Mitigation Recommendations
Red Hat has released updated python3.12 packages that fix these vulnerabilities. Users should apply the security update for python3.12 as provided in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and other affected variants. Detailed update instructions are available at https://access.redhat.com/articles/11258. Applying these updates will remediate the vulnerabilities. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:17525
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-6100"]
- State
- PUBLISHED
Threat ID: 6a175eeee29bf47b50edd246
Added to database: 05/27/2026, 21:15:26 UTC
Last enriched: 08/10/2026, 20:07:01 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.