python3-3.6.8-76.el8_10.ML.1

エラータID: AXSA:2026-547:06

Release date: 
Thursday, May 7, 2026 - 10:24
Subject: 
python3-3.6.8-76.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100)
* python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-4786
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVE-2026-6100
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python3-3.6.8-76.el8_10.ML.1.src.rpm
    MD5: 55931a49130a07de16217070289abfc4
    SHA-256: f286ff7424d83fdb9a818f79f9e7b35a300bad93396459c91670ae3142744dfc
    Size: 18.36 MB

Asianux Server 8 for x86_64
  1. platform-python-3.6.8-76.el8_10.ML.1.i686.rpm
    MD5: 88f09e34fadce9a9f7d4c292cd93ca9a
    SHA-256: 1a8012ce8014babbb95fb94fa59b5dad4899cc6c41eaad0b6b587d9218506dc4
    Size: 88.48 kB
  2. platform-python-3.6.8-76.el8_10.ML.1.x86_64.rpm
    MD5: d4f03ecc3ffe5d4dd6eab955420e448e
    SHA-256: 3da93aee34a299e014aa51ba4bf389183cb937178b7507fb5c08e72dfb257331
    Size: 88.55 kB
  3. platform-python-debug-3.6.8-76.el8_10.ML.1.i686.rpm
    MD5: 099723a55db349b6974f8ba1478b9165
    SHA-256: 3d6d3453192f56e262b4fe3d17718eae17b5721ac047f96a0be1d82013eb0f78
    Size: 2.72 MB
  4. platform-python-debug-3.6.8-76.el8_10.ML.1.x86_64.rpm
    MD5: 7284226c7eaac09b35bdac5901fafc5d
    SHA-256: 31df26100487018eb2b98d97c099c2c5c417b7fcd205fc0f82c557640725e279
    Size: 2.68 MB
  5. platform-python-devel-3.6.8-76.el8_10.ML.1.i686.rpm
    MD5: 0506f8b1c4cfee017949d98315e204a9
    SHA-256: d1748e8464fa85fc5a7112b779f11b193800406bc1757e5567d0b424901195be
    Size: 241.82 kB
  6. platform-python-devel-3.6.8-76.el8_10.ML.1.x86_64.rpm
    MD5: 41f9f0031ca66a3df736f976fce88acc
    SHA-256: dc7324c4924163258f29828cf551763a6d9b25ab9c0e0315a80b7c441ae34faf
    Size: 242.05 kB
  7. python3-idle-3.6.8-76.el8_10.ML.1.i686.rpm
    MD5: 07f95ed723206ee9b98e5f580c2b301f
    SHA-256: 6cbd2a56b37e6caab47fb4f7120087ac922e74c57c99ea86f993f4d9d861bf74
    Size: 829.92 kB
  8. python3-idle-3.6.8-76.el8_10.ML.1.x86_64.rpm
    MD5: a13bf07349a85ea86130143411f2d6c7
    SHA-256: c1b4cd54fcb8da7ef7cd9b008912f7fa07346f50488136e9d6c45e56a6e5f4fa
    Size: 829.90 kB
  9. python3-libs-3.6.8-76.el8_10.ML.1.i686.rpm
    MD5: 238946ab81adc51f2b94650ee0a713fa
    SHA-256: 3141fac3be81c8f68c784da4bbcde2bbb10848da09d0931e78e662dd564ecebe
    Size: 7.91 MB
  10. python3-libs-3.6.8-76.el8_10.ML.1.x86_64.rpm
    MD5: aea78fb05d35af9b0e61d47e76707912
    SHA-256: 511a1953b753a9b6972ed3cba43f1f50b2152a6845903db5efcdda8285b817d8
    Size: 7.84 MB
  11. python3-test-3.6.8-76.el8_10.ML.1.i686.rpm
    MD5: 0617e8c95019fec0c0d874fa38245de5
    SHA-256: 81d6408aed6bd88d21c51f1f866011ff87d847739f1eca6896b1defdd7993621
    Size: 8.70 MB
  12. python3-test-3.6.8-76.el8_10.ML.1.x86_64.rpm
    MD5: 31d40e1e7802395ecffbec3850fe74b3
    SHA-256: b363f6fdec462c3dcc83be1007a52ba13426b6ff93a70f5090030d3fa73e2b91
    Size: 8.71 MB
  13. python3-tkinter-3.6.8-76.el8_10.ML.1.i686.rpm
    MD5: 755e5a5141cc6670d0688523093d4558
    SHA-256: 390670a94e53b437fbd46674709293e63d226b2f2ea314acc95994766fdba67b
    Size: 376.68 kB
  14. python3-tkinter-3.6.8-76.el8_10.ML.1.x86_64.rpm
    MD5: 8db42e8976ba7832d446aa1d747d0b3e
    SHA-256: c0a1385c77aaf0bae00b5688e5f7886f242d9940f36e171f70f2d9b501f1de9b
    Size: 375.23 kB