Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-19445 — python: Use-after-free of a server-side SSLContext when sni_callback switches contexts
🎯 Affected products30
- Red Hat Hardened Images
- python3.15-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-0:3.15.0~rc2-1.1.hum1@src as a component of Red Hat Hardened Images
- python3.15-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-debug-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-debug-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-devel-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-devel-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-freethreading-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-freethreading-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-freethreading-debug-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-freethreading-debug-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-freethreading-devel-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-freethreading-devel-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-freethreading-idle-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-freethreading-idle-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-freethreading-libs-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-freethreading-libs-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-freethreading-test-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-freethreading-test-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-freethreading-tkinter-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-freethreading-tkinter-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-idle-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-idle-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-libs-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-libs-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-test-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-test-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
- python3.15-tkinter-0:3.15.0~rc2-1.1.hum1@aarch64 as a component of Red Hat Hardened Images
- python3.15-tkinter-0:3.15.0~rc2-1.1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Restrict Python TLS servers that use SSLContext.sni_callback to trusted clients ([CME-202](https://cmetaxonomy.org/entries/CME-202.html)). Keep a strong reference to every SSLContext that registers an SNI callback for the lifetime of the server so the original context cannot be garbage-collected while connections remain open. Prefer wrapping the listening socket with a long-lived SSLContext; that common pattern is not affected. Host heap allocator hardening ([CME-117](https://cmetaxonomy.org/entries/CME-117.html)) increases the difficulty of turning the use-after-free into reliable code execution but does not prevent process crashes.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:74867
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-19445
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74867.json