RHSA-2026:74867HighCVSS 8.1

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
October 2, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-19445 — python: Use-after-free of a server-side SSLContext when sni_callback switches contexts

🎯 Affected products30

  • Red Hat Hardened Images
  • python3.15-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-0:3.15.0~rc2-1.1.hum1@src as a component of Red Hat Hardened Images
  • python3.15-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-debug-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-debug-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-devel-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-devel-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-debug-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-debug-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-devel-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-devel-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-idle-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-idle-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-libs-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-libs-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-test-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-test-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-tkinter-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-freethreading-tkinter-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-idle-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-idle-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-libs-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-libs-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-test-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-test-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
  • python3.15-tkinter-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
  • python3.15-tkinter-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Restrict Python TLS servers that use SSLContext.sni_callback to trusted clients ([CME-202](https://cmetaxonomy.org/entries/CME-202.html)). Keep a strong reference to every SSLContext that registers an SNI callback for the lifetime of the server so the original context cannot be garbage-collected while connections remain open. Prefer wrapping the listening socket with a long-lived SSLContext; that common pattern is not affected. Host heap allocator hardening ([CME-117](https://cmetaxonomy.org/entries/CME-117.html)) increases the difficulty of turning the use-after-free into reliable code execution but does not prevent process crashes.

🔗 References (5)