CVE-2025-4138

high
Published 2025-07-01 ยท Modified 2025-12-18
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2025:23530: python39:3.9 security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory Red Hat statement Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language. CVSS v3: 7.5โ€ฆ

Description

cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

Red Hat statement

Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10python3.12-0:3.12.9-2.el10_0.2RHSA-2025:101402025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python3.11-0:3.11.13-1.el8_10RHSA-2025:100262025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python3.12-0:3.12.11-1.el8_10RHSA-2025:100312025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python3-0:3.6.8-70.el8_10RHSA-2025:101282025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python39:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python39-devel:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python39:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python39-devel:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python3-0:3.6.8-70.el8_10RHSA-2025:101282025-07-01T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportpython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-Onpython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicepython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionspython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-Onpython3-0:3.6.8-51.el8_8.10RHSA-2025:106022025-07-08T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicepython3-0:3.6.8-51.el8_8.10RHSA-2025:106022025-07-08T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionspython3-0:3.6.8-51.el8_8.10RHSA-2025:106022025-07-08T00:00:00Z
Red Hat Enterprise Linux 9python3.9-0:3.9.21-2.el9_6.1RHSA-2025:101362025-07-01T00:00:00Z
Red Hat Enterprise Linux 9python3.11-0:3.11.11-2.el9_6.1RHSA-2025:101482025-07-01T00:00:00Z
Red Hat Enterprise Linux 9python3.12-0:3.12.9-1.el9_6.1RHSA-2025:101892025-07-02T00:00:00Z
Red Hat Enterprise Linux 9python3.9-0:3.9.21-2.el9_6.1RHSA-2025:101362025-07-01T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpython3.12-0:3.12.1-4.el9_4.6RHSA-2025:100282025-07-01T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpython3.9-0:3.9.18-3.el9_4.8RHSA-2025:103992025-07-07T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpython3.11-0:3.11.7-1.el9_4.8RHSA-2025:99182025-06-30T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1752066672RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1752065732RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-controller-rhel8:7.13.5-4.1752065732RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752065737RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752065731RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-operator-bundle:7.13.5-25RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752065736RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-rhel8-operator:7.13.5-2.1752065733RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752065755RHSA-2025:113862025-07-17T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-management-console-rhel8:1.36.0-9RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-rhel8-operator:1.36.0-18RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7RHSA-2026:09342026-01-22T00:00:00Z
cert-manager operator for Red Hat OpenShift 1.16cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757RHSA-2025:182192025-10-16T00:00:00Z
Red Hat Discovery 2discovery/discovery-server-rhel9:2.0.1-1754478727RHSA-2025:132672025-08-06T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Apply commands

bash fix
Apply RHSA-2025:10140 for Red Hat Enterprise Linux 10
yum update -y python3
# or:
dnf upgrade -y python3

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat OpenShift Container Platform 4Not affected

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
redhat rhel9fixed
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0
suse slesaffected
rockylinux rocky9fixed
almalinux almalinux9fixedpython-unversioned-command-3.9.21-2.el9_6.1.noarch.rpm
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.