python3.12-3.12.15-2.el8_10

エラータID: AXSA:2026-1997:24

Release date: 
Thursday, October 8, 2026 - 20:33
Subject: 
python3.12-3.12.15-2.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* python: python: Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio() (CVE-2026-19553)
* python: Use-after-free of a server-side SSLContext when sni_callback switches contexts (CVE-2026-19445)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-19445
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected.
CVE-2026-19553
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python3.12-3.12.15-2.el8_10.src.rpm
    MD5: e1cba6ff3ab7c9397b6f0b4e545b8994
    SHA-256: 4f6af219fd7aede032cdbbc671ffc10d72032f3c7c95c35e115b2ebf487f8d92
    Size: 19.94 MB

Asianux Server 8 for x86_64
  1. python3.12-3.12.15-2.el8_10.i686.rpm
    MD5: 313ee143eb8b260e8fed7766421c817d
    SHA-256: 0fd5e3b491d568527f4a5e618ae205ebf173aa3e308849cf22311271a458cd1a
    Size: 31.66 kB
  2. python3.12-3.12.15-2.el8_10.x86_64.rpm
    MD5: 14fb6dbc75b5210845c3382107be6d81
    SHA-256: b9f7d1d03f9ab36bc9d36926e494b853f08370efd3c683d30eb39f1522438c43
    Size: 31.56 kB
  3. python3.12-debug-3.12.15-2.el8_10.i686.rpm
    MD5: 765058f865eaf0b60de7b8b313dec517
    SHA-256: 9704d3b9abed95ca46ab427727c4be05e75b4b14ad814a4704682763be5a6b36
    Size: 3.50 MB
  4. python3.12-debug-3.12.15-2.el8_10.x86_64.rpm
    MD5: 830a6cad5b320cdee622c5d0e5870904
    SHA-256: db58da713daa2a058df959bd7c645e7d8294cd3a0d09e19c71b85dc158722dcc
    Size: 3.69 MB
  5. python3.12-devel-3.12.15-2.el8_10.i686.rpm
    MD5: 4a3a78c09c54e10e18b483b9862fe9c4
    SHA-256: 83cc8072b7b19a061eb5f5594ab37f8e4807fb651cba726dac32bff440feb12d
    Size: 293.04 kB
  6. python3.12-devel-3.12.15-2.el8_10.x86_64.rpm
    MD5: 29f3bd2a4e6a6b54deef2ae13730bfbb
    SHA-256: fbadf219d152462d84e9d0ae9ab0123474f2dd9654b235793e5f3254a2221306
    Size: 292.95 kB
  7. python3.12-idle-3.12.15-2.el8_10.i686.rpm
    MD5: c156d96b95609697e5dd91275fb2d554
    SHA-256: 35640f4ff0a33c051039fc753cf62825daec8c47b652192a6d48a40c1451670a
    Size: 1.29 MB
  8. python3.12-idle-3.12.15-2.el8_10.x86_64.rpm
    MD5: ee6cf80f55b32a52ca931e7fa221080a
    SHA-256: 97322cc4095884b35148a76fb14971bf5151d307ee3a247fee166d88dd1431b1
    Size: 1.29 MB
  9. python3.12-libs-3.12.15-2.el8_10.i686.rpm
    MD5: 962f6c3972ca8ed7994f7c10a097c053
    SHA-256: 09d2924a31cc6fb4c3838e2a40d186b5c447c6e3801afc833802d8b04fbaabd3
    Size: 10.12 MB
  10. python3.12-libs-3.12.15-2.el8_10.x86_64.rpm
    MD5: 249bf073c1ccc27d2ba7b57a6f16e3ec
    SHA-256: 93538049ac839923435dff7c45be4ecca23cfa23113f8b9ef278f6ef02f6dcf5
    Size: 10.04 MB
  11. python3.12-rpm-macros-3.12.15-2.el8_10.noarch.rpm
    MD5: cb61f9fa77af83c5fc00ba1069a2a263
    SHA-256: 43d39a417850f3c1f709c2fa41db56228b9192e96e83441ad9b34cc03ffaaff8
    Size: 18.18 kB
  12. python3.12-test-3.12.15-2.el8_10.i686.rpm
    MD5: d112e8275452d05944542f09735227d8
    SHA-256: b801a1943f28814d7513dc4e575bbe7f4265feb2b1bd80bfbc4c04bae0ed9c11
    Size: 16.05 MB
  13. python3.12-test-3.12.15-2.el8_10.x86_64.rpm
    MD5: cb914a411f6d70edbaa77f7c97642542
    SHA-256: 569f3ce0f91bd871fb32fb422317e169586739a665e5e4390a475a9f68b7c120
    Size: 16.04 MB
  14. python3.12-tkinter-3.12.15-2.el8_10.i686.rpm
    MD5: e4c38366576b6b84f14d46d8eb3c1ee7
    SHA-256: 6af4655fad5c5f765590ea0c30a674ba47bf5709db6b0872d532a7cf6a2cd2da
    Size: 404.37 kB
  15. python3.12-tkinter-3.12.15-2.el8_10.x86_64.rpm
    MD5: 2572f7bb6fadd3d049942902c48f6d08
    SHA-256: a029b92cd547c37ad64f35f5c1007e8649b2110aa24a76a6426a0c16c1396d68
    Size: 403.40 kB