Skip to main content
EPSS 0.4%top 69%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
Low
Published: 07/29/2026 (07/29/2026, 22:11:16 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: python3.12: * python3.12-3.12.13-3.8.hum1 (aarch64, x86_64) * python3.12-debug-3.12.13-3.8.hum1 (aarch64, x86_64) * python3.12-devel-3.12.13-3.8.hum1 (aarch64, x86_64) * python3.12-idle-3.12.13-3.8.hum1 (aarch64, x86_64) * python3.12-libs-3.12.13-3.8.hum1 (aarch64, x86_64) * python3.12-test-3.12.13-3.8.hum1 (aarch64, x86_64) * python3.12-tkinter-3.12.13-3.8.hum1 (aarch64, x86_64) * python3.12-3.12.13-3.8.hum1.src (src) Security Fix(es): python3.12: * CVE-2026-6879

Affected software

Affected versions
=0=3.11.0=3.12.0=3.13.0=3.14.0=3.15.0>=3.11.0 <3.13.14>=3.12.0 <3.13.14>=3.13.0 <3.13.14>=3.14.0 <3.13.14Red HatRed Hat Hardened Imagesaarch64python3-10-main@aarch64python3-11-main@aarch64python3-13-main@aarch64<3.10.21>=3.11.0 <3.11.16>=3.12.0 <3.12.14>=3.13.0 <3.13.15>=3.14.0 <3.14.7python3-12-main@aarch64noarchpython3-14-main@noarch

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:06:19 UTC

Technical Analysis

CVE-2026-6879 is a vulnerability in Python's xml.etree.ElementPath component that leads to denial of service through resource exhaustion. Specifically, certain XPath index predicates used with Element.findall() and Element.iterfind() cause processing time to grow quadratically with input size. This can be exploited by a remote attacker providing malicious XML files to cause service disruption. The vulnerability is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-407. Red Hat has released updated python3.13 RPM packages for their Hardened Images to address this issue, as detailed in advisory RHSA-2026:48278.

Potential Impact

The vulnerability allows a remote attacker to cause a denial of service by supplying specially crafted XML documents that trigger excessive CPU and memory consumption during XML processing. This can make affected systems unresponsive, impacting service availability. There is no impact on confidentiality or integrity. The severity is rated low by Red Hat due to the high attack complexity and requirement for privileges.

Mitigation Recommendations

Red Hat has released updated python3.13 RPM packages for Red Hat Hardened Images that fix this vulnerability. Users should apply the security update as described in Red Hat Advisory RHSA-2026:48278. No additional mitigations are specified or required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:48278
Cve Count
1
State
PUBLISHED

Threat ID: 6a7891c4bf8831d539c859d5

Added to database: 08/09/2026, 14:42:12 UTC

Last enriched: 08/16/2026, 18:06:19 UTC

Last updated: 09/24/2026, 01:47:44 UTC

Views: 61

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses