Описание
ELSA-2026-35838: python3 security update (IMPORTANT)
[3.6.8-21.0.13]
- Security update CVE-2026-4786 [Orabug: 39695277]
[3.6.8-21.0.11]
- Security update CVE-2026-4519 [Orabug: 39246828]
[3.6.8-21.0.9]
- Security update CVE-2025-15366, CVE-2025-15367, CVE-2026-1299 [Orabug: 39159999]
[3.6.8-21.0.7]
- Security update CVE-2025-12084 [Orabug: 38971895]
[3.6.8-21.0.5]
- tarfile now validates archives to ensure member offsets are non-negative [Orabug: 38442771][CVE-2025-8194]
[3.6.8-21.0.3]
- Fix DoS parsing crafted tarfile headers [Orabug: 37626372][CVE-2024-6232]
- Disable test_socket in the PGO profile task.
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
python3
3.6.8-21.0.13.el7_9
python3-debug
3.6.8-21.0.13.el7_9
python3-devel
3.6.8-21.0.13.el7_9
python3-idle
3.6.8-21.0.13.el7_9
python3-libs
3.6.8-21.0.13.el7_9
python3-test
3.6.8-21.0.13.el7_9
python3-tkinter
3.6.8-21.0.13.el7_9
Связанные CVE
Связанные уязвимости
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...