python3-3.6.8-73.el8_10.ML.1
エラータID: AXSA:2026-153:02
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
* cpython: wsgiref.headers.Headers allows header newline injection in Python (CVE-2026-0865)
* cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)
* cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)
* cpython: email header injection due to unquoted newlines (CVE-2026-1299)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2025-15366
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-15367
The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2026-0865
User-controlled header names and values containing newlines can allow injecting HTTP headers.
CVE-2026-1299
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
Update packages.
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
User-controlled header names and values containing newlines can allow injecting HTTP headers.
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
N/A
SRPMS
- python3-3.6.8-73.el8_10.ML.1.src.rpm
MD5: 7b565ddf002e31def3adf0f4d8d80d0b
SHA-256: add13646fc8875aa876bff01454ae4ac3b324950c2417cdd3d61bc44036e83b4
Size: 18.36 MB
Asianux Server 8 for x86_64
- platform-python-3.6.8-73.el8_10.ML.1.i686.rpm
MD5: baeee51ec2aeff8e5bc74a4afada9a87
SHA-256: 83cd9be039d54af4fa65aed6ccf820eb944263a01a5b1fc26c1941ffee585f3d
Size: 88.16 kB - platform-python-3.6.8-73.el8_10.ML.1.x86_64.rpm
MD5: 91cbd08b0764b5555255b7a249d5f183
SHA-256: 13cbcbcbf7a9387dd3da2e941787727f546928233a8cdad1a6c480f78ed07c7c
Size: 88.23 kB - platform-python-debug-3.6.8-73.el8_10.ML.1.i686.rpm
MD5: f360fda5af3c310ddd7ebf165ea860d3
SHA-256: a98d12fd816ede17f6bdc8b0fde9d314fc2f7b5c9487897050ac2b2f8166284f
Size: 2.72 MB - platform-python-debug-3.6.8-73.el8_10.ML.1.x86_64.rpm
MD5: 2f615cac4750925a96935657b1cb9791
SHA-256: ff9fc36b10acad4295248a5c4c95a11212aa7f740efbb14078d00ecc72dadbf3
Size: 2.68 MB - platform-python-devel-3.6.8-73.el8_10.ML.1.i686.rpm
MD5: 076c334dc8fed2f00a020f5657393854
SHA-256: 9bf8281efe5df043c929aae1e895ffcc6394260ba61d7cc4420b77b3466c160d
Size: 241.49 kB - platform-python-devel-3.6.8-73.el8_10.ML.1.x86_64.rpm
MD5: d5c8cd8850a00a44c2a689afa960828a
SHA-256: 3f7ba23479096d8baba8839cd4be0037756a22083c5e12bed05d27c252e4615b
Size: 241.73 kB - python3-idle-3.6.8-73.el8_10.ML.1.i686.rpm
MD5: 1631a7e0d101ff290f611a1ebb27d761
SHA-256: c82c780352c756cc89eb3bf6ee85d5ee280903ca654f2cdaf377b595733b4ebf
Size: 829.58 kB - python3-idle-3.6.8-73.el8_10.ML.1.x86_64.rpm
MD5: 53cf6c651f103efbeee811b9a521e27f
SHA-256: 3cc92afecf3eab34f69f11fcf46112db5804c3dfc8ff68c0733e057d4f783815
Size: 829.56 kB - python3-libs-3.6.8-73.el8_10.ML.1.i686.rpm
MD5: 3a14ff61c37456e7e815e49f2cb6b8d9
SHA-256: b28abf5c1b489f7c0bde419f343d33dff735343c66f88f3dbaf7740ba94465fb
Size: 7.91 MB - python3-libs-3.6.8-73.el8_10.ML.1.x86_64.rpm
MD5: 88f5304caa385fddf21332b9d5597572
SHA-256: eb68c86690a8c8957163b20480a04d0238d4d251ee8aaea408f3c1c639e18abc
Size: 7.84 MB - python3-test-3.6.8-73.el8_10.ML.1.i686.rpm
MD5: 4aba1545103e29aff3fb61797cae722a
SHA-256: 54a175f77b3f57755253a2609cb4f63a0c4214ebba46a182210010d54a960491
Size: 8.70 MB - python3-test-3.6.8-73.el8_10.ML.1.x86_64.rpm
MD5: d1396fce550d3b9f144da6ac5c642d49
SHA-256: a76c3869060168fb7f434f0758be8400ec9059ba50bf2cbbe277089658ec0939
Size: 8.71 MB - python3-tkinter-3.6.8-73.el8_10.ML.1.i686.rpm
MD5: 256023d4ad4041f2ff9b481716eb5bf6
SHA-256: 1743894298b7d7485f0623d2b74df6e9052d56bca1de1b109d15fc62daa1f209
Size: 376.45 kB - python3-tkinter-3.6.8-73.el8_10.ML.1.x86_64.rpm
MD5: eb591df90035961a855a37dfd86811aa
SHA-256: 1892feb22306451621138e5d6775244dcde8405c7407f43fed4fa18d45b9da93
Size: 374.90 kB