Moderate: python3.12 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4713", "synopsis": "Moderate: python3.12 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for python3.12.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.\n\nSecurity Fix(es):\n\n* cpython: wsgiref.headers.Headers allows header newline injection in Python (CVE-2026-0865)\n\n* cpython: IMAP command injection in user-controlled commands (CVE-2025-15366)\n\n* cpython: POP3 command injection in user-controlled commands (CVE-2025-15367)\n\n* cpython: email header injection due to unquoted newlines (CVE-2026-1299)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2431368", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431368", "description": ""}, {"ticket": "2432437", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2432437", "description": ""}, {"ticket": "2431373", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431373", "description": ""}, {"ticket": "2431367", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431367", "description": ""}], "cves": [{"name": "CVE-2025-15366", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15366", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N", "cvss3BaseScore": "7.1", "cwe": "CWE-77"}, {"name": "CVE-2025-15367", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-15367", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N", "cvss3BaseScore": "7.1", "cwe": "CWE-77"}, {"name": "CVE-2026-0865", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-0865", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N", "cvss3BaseScore": "4.5", "cwe": "CWE-74"}, {"name": "CVE-2026-1299", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-1299", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N", "cvss3BaseScore": "7.1", "cwe": "CWE-93"}], "references": [], "publishedAt": "2026-03-27T12:07:50.770013Z", "rpms": {"Rocky Linux 10": {"nvras": ["python3-debug-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3.12-debugsource-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3-test-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3-debug-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3-idle-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3.12-debugsource-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3-devel-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3.12-debuginfo-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-libs-0:3.12.12-3.el10_1.1.s390x.rpm", "python3-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3.12-debuginfo-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3-debug-0:3.12.12-3.el10_1.1.s390x.rpm", "python3.12-debuginfo-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3.12-0:3.12.12-3.el10_1.1.src.rpm", "python3.12-debugsource-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-libs-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3-test-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-tkinter-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3-test-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3-idle-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3-tkinter-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3-libs-0:3.12.12-3.el10_1.1.ppc64le.rpm","python3.12-debuginfo-0:3.12.12-3.el10_1.1.s390x.rpm", "python3-tkinter-0:3.12.12-3.el10_1.1.s390x.rpm", "python3-tkinter-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-devel-0:3.12.12-3.el10_1.1.s390x.rpm", "python-unversioned-command-0:3.12.12-3.el10_1.1.noarch.rpm", "python3.12-debugsource-0:3.12.12-3.el10_1.1.s390x.rpm", "python3-libs-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-idle-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-devel-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-0:3.12.12-3.el10_1.1.aarch64.rpm", "python3-idle-0:3.12.12-3.el10_1.1.s390x.rpm", "python3-devel-0:3.12.12-3.el10_1.1.ppc64le.rpm", "python3-0:3.12.12-3.el10_1.1.s390x.rpm", "python3-debug-0:3.12.12-3.el10_1.1.x86_64.rpm", "python3-test-0:3.12.12-3.el10_1.1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate security update for python3.12 on Rocky Linux 10 to fix several command injection issues.. python3 security update, Rocky Linux advisory, moderate fix, command injection issue. . LinuxSecurity.com Team
nginx-mod-fancyindex: Rebuild for 1.28.2 nginx-mod-headers-more: Rebuild for 1.28.2 nginx-mod-brotli:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0b8cc86e5b 2026-02-15 01:28:07.972874+00:00 -------------------------------------------------------------------------------- Name : nginx-mod-headers-more Product : Fedora 42 Version : 0.39 Release : 6.fc42 URL : https://github.com/openresty/headers-more-nginx-module Summary : This module allows adding, setting, or clearing specified input/output headers Description : This module allows adding, setting, or clearing specified input/output headers. This is an enhanced version of the standard headers module because it provides more utilities like resetting or clearing "builtin headers" like Content-Type, Content-Length, and Server. -------------------------------------------------------------------------------- Update Information: nginx-mod-fancyindex: Rebuild for 1.28.2 nginx-mod-headers-more: Rebuild for 1.28.2 nginx-mod-brotli: Rebuild for 1.28.2 nginx-mod-modsecurity: Rebuild for 1.28.2 nginx-mod-vts: Rebuild for 1.28.2 nginx-mod-naxsi: Rebuild for 1.28.2 nginx: Update to 1.28.2 fixes CVE-2026-1642 move log directory to nginx-filesystem subpackage (PR#20) delete Maxim Dounin's key, it's no longer listed on the nginx website -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 4 2026 Felix Kaechele - 0.39-6 - Rebuild for 1.28.2 * Fri Jan 16 2026 Fedora Release Engineering - 0.39-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2436870 - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2436870 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0b8cc86e5b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-57fd391bf8 2022-02-05 01:21:20.736042 --------------------------------------------------------------------------------Name : kernel-headers Product : Fedora 35 Version : 5.16.5 Release : 200.fc35 URL : https://www.kernel.org/ Summary : Header files for the Linux kernel for use by glibc Description : Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. --------------------------------------------------------------------------------Update Information: The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 1 2022 Justin M. Forbes - 5.16.5-200 - Linux v5.16.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #2048492 - CVE-2022-24122 kernel: use-after-free and privilege escalation in kernel/ucount.c when unprivileged user namespaces are enabled https://bugzilla.redhat.com/show_bug.cgi?id=2048492 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-57fd391bf8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The 5.11.14 stable kernel update contains a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-d56567bdab 2021-04-24 20:00:51.080627 --------------------------------------------------------------------------------Name : kernel-headers Product : Fedora 34 Version : 5.11.14 Release : 300.fc34 URL : https://www.kernel.org/ Summary : Header files for the Linux kernel for use by glibc Description : Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. --------------------------------------------------------------------------------Update Information: The 5.11.14 stable kernel update contains a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Wed Apr 14 2021 Justin M. Forbes - 5.11.14-300 - Linux v5.11.14 --------------------------------------------------------------------------------References: [ 1 ] Bug #1894550 - CVE-2020-25670 kernel: refcount leak in llcp_sock_bind() https://bugzilla.redhat.com/show_bug.cgi?id=1894550 [ 2 ] Bug #1894552 - CVE-2020-25671 kernel: refcount leak in llcp_sock_connect() https://bugzilla.redhat.com/show_bug.cgi?id=1894552 [ 3 ] Bug #1894556 - CVE-2020-25672 kernel: memory leak in llcp_sock_connect() https://bugzilla.redhat.com/show_bug.cgi?id=1894556 [ 4 ] Bug #1894558 - CVE-2020-25673 kernel: non-blocking socket in llcp_sock_connect() https://bugzilla.redhat.com/show_bug.cgi?id=1894558 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2021-d56567bdab' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.