Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: python3.12: * python3.12-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-debug-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-devel-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-idle-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-libs-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-test-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-tkinter-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-3.12.13-3.5.hum1.src (src) Security Fix(es): python3.12: * CVE-2025-4330 * CVE-2026-11940 * CVE-2026-15308
AI Analysis
Technical Summary
This Red Hat security advisory addresses vulnerabilities in the python3.12 RPM packages used in Red Hat Hardened Images. The primary issue, CVE-2025-4330, is a flaw in the CPython tarfile module that allows attackers to bypass extraction filters and perform symlink traversal outside the intended extraction directory. This can lead to overwriting or modifying critical system files and metadata when a malicious tar archive is extracted using TarFile.extractall() or TarFile.extract() with specific filters. Exploitation requires a privileged user or process to extract the malicious archive, which reduces the risk. The advisory also addresses CVE-2026-11940 and CVE-2026-15308. Red Hat provides updated python3.12 RPM packages for aarch64 and x86_64 architectures to remediate these issues. The advisory notes no known exploits in the wild and no available mitigations that meet Red Hat's criteria. The severity is classified as high.
Potential Impact
Successful exploitation of CVE-2025-4330 could allow an attacker to overwrite or modify critical system files and metadata by bypassing extraction filters in the tarfile module. This may lead to unauthorized code execution, integrity compromise, and potential confidentiality breaches if sensitive files are read or modified. However, exploitation requires a privileged user or process to extract a malicious tar archive, limiting the attack vector. No known exploits in the wild have been reported. The overall impact is high due to the potential for system file modification and code execution.
Mitigation Recommendations
A security update is available from Red Hat that includes patched python3.12 RPM packages addressing these vulnerabilities. Users should apply the updated packages (e.g., python3.12-3.12.13-3.5.hum1) from the Red Hat Hardened Images repository. No alternative mitigations meeting Red Hat's criteria are currently available. Since exploitation requires privileged user action to extract malicious archives, cautious handling of tar files and limiting extraction of untrusted archives can reduce risk. Refer to the official Red Hat advisory (RHSA-2026:38017) for update instructions.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: python3.12: * python3.12-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-debug-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-devel-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-idle-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-libs-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-test-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-tkinter-3.12.13-3.5.hum1 (aarch64, x86_64) * python3.12-3.12.13-3.5.hum1.src (src) Security Fix(es): python3.12: * CVE-2025-4330 * CVE-2026-11940 * CVE-2026-15308
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory addresses vulnerabilities in the python3.12 RPM packages used in Red Hat Hardened Images. The primary issue, CVE-2025-4330, is a flaw in the CPython tarfile module that allows attackers to bypass extraction filters and perform symlink traversal outside the intended extraction directory. This can lead to overwriting or modifying critical system files and metadata when a malicious tar archive is extracted using TarFile.extractall() or TarFile.extract() with specific filters. Exploitation requires a privileged user or process to extract the malicious archive, which reduces the risk. The advisory also addresses CVE-2026-11940 and CVE-2026-15308. Red Hat provides updated python3.12 RPM packages for aarch64 and x86_64 architectures to remediate these issues. The advisory notes no known exploits in the wild and no available mitigations that meet Red Hat's criteria. The severity is classified as high.
Potential Impact
Successful exploitation of CVE-2025-4330 could allow an attacker to overwrite or modify critical system files and metadata by bypassing extraction filters in the tarfile module. This may lead to unauthorized code execution, integrity compromise, and potential confidentiality breaches if sensitive files are read or modified. However, exploitation requires a privileged user or process to extract a malicious tar archive, limiting the attack vector. No known exploits in the wild have been reported. The overall impact is high due to the potential for system file modification and code execution.
Mitigation Recommendations
A security update is available from Red Hat that includes patched python3.12 RPM packages addressing these vulnerabilities. Users should apply the updated packages (e.g., python3.12-3.12.13-3.5.hum1) from the Red Hat Hardened Images repository. No alternative mitigations meeting Red Hat's criteria are currently available. Since exploitation requires privileged user action to extract malicious archives, cautious handling of tar files and limiting extraction of untrusted archives can reduce risk. Refer to the official Red Hat advisory (RHSA-2026:38017) for update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:38017
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-15308"]
- Cvss Version
- null
Threat ID: 6a520eb168715ace438f4fd7
Added to database: 07/11/2026, 09:36:49 UTC
Last enriched: 08/16/2026, 17:56:59 UTC
Last updated: 08/25/2026, 22:52:06 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.