Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (5)
📋 Description
CVE-2025-15366 — cpython: IMAP command injection in user-controlled commands CVE-2026-1502 — python: Python: HTTP header injection via CR/LF in proxy tunnel headers CVE-2026-4786 — python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API CVE-2026-5713 — python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. CVE-2026-6100 — python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules
🎯 Affected products5
- Red Hat Hardened Images
- python3-14-main@aarch64 as a component of Red Hat Hardened Images
- python3-14-main@noarch as a component of Red Hat Hardened Images
- python3-14-main@src as a component of Red Hat Hardened Images
- python3-14-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this vulnerability, ensure that no data passed to the imaplib module contains newline or carriage return characters. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:9228
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-4786
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-5713
- externalhttps://access.redhat.com/security/cve/CVE-2026-6100
- externalhttps://access.redhat.com/security/cve/CVE-2026-1502
- externalhttps://access.redhat.com/security/cve/CVE-2025-15366
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_9228.json