Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 42 python3.12 Important Command Injection Fixes 2026-3ebfc12a16

fedora
Calendar Grey March 13, 2026
Dist Fedora Esm H88
Update to Fedora 42's python3.12 includes crucial security fixes for serious command injection issues.
Update to 3.12.13 Security fixes for CVE-2026-1299, CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367

Summary

Python 3.12 is an accessible, high-level, dynamically typed, interpreted

programming language, designed with an emphasis on code readability.

It includes an extensive standard library, and has a vast ecosystem of

third-party libraries.

The python3.12 package provides the "python3.12" executable: the reference

interpreter for the Python language, version 3.

The majority of its standard library is provided in the python3.12-libs package,

which should be installed automatically along with python3.12.

The remaining parts of the Python standard library are broken out into the

python3.12-tkinter and python3.12-test packages, which may need to be installed

separately.

Documentation for Python is provided in the python3.12-docs package.

Packages containing additional libraries for Python are generally named with

the "python3.12-" prefix.

Update Information:

Update to 3.12.13 Security fixes for CVE-2026-1299, CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367

Change Log

* Tue Mar 3 2026 Tom\u0161 Hrn\u010diar - 3.12.13-1 - Update to 3.12.13 * Fri Feb 6 2026 Tom\u0161 Hrn\u010diar - 3.12.12-4 - Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367

References


[ 1 ] Bug #2431617 - CVE-2025-15366 python3.12: IMAP command injection in user-controlled commands [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431617 [ 2 ] Bug #2431641 - CVE-2025-15367 python3.12: POP3 command injection in user-controlled commands [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431641 [ 3 ] Bug #2431764 - CVE-2025-11468 python3.12: Missing character filtering in Python [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431764 [ 4 ] Bug #2431787 - CVE-2026-0672 python3.12: Header injection in http.cookies.Morsel in Python [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431787 [ 5 ] Bug #2431793 - CVE-2026-0865 python3.12: wsgiref.headers.Headers allows header newline injection in Python [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431793 [ 6 ] Bug #2431808 - CVE-2025-15282 python3.12: Header injection via newlines in data URL mediatype in Python [fedora-42] h...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3ebfc12a16' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python3.12
Product: Fedora 42
Version: 3.12.13
Release: 1.fc42
Summary: Version 3.12 of the Python interpreter

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here