RHSA-2025:10602HighCVSS 7.6

Red Hat Security Advisory: python3 security update

Published
July 8, 2025
Last Modified
July 10, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-12718 — cpython: python: Bypass extraction filter to modify file metadata outside extraction directory CVE-2025-4138 — cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory CVE-2025-4330 — cpython: python: Extraction filter bypass for linking outside extraction directory CVE-2025-4435 — cpython: Tarfile extracts filtered members when errorlevel=0 CVE-2025-4517 — python: cpython: Arbitrary writes via tarfile realpath overflow

🔗 References (8)