CVE-2025-4138

high
Published 2025-07-01 ยท Modified 2025-07-02
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

Important: python3.9 security update

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory Red Hat statement Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language. CVSS v3: 7.5โ€ฆ

Description

cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory

Red Hat statement

Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10python3.12-0:3.12.9-2.el10_0.2RHSA-2025:101402025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python3.11-0:3.11.13-1.el8_10RHSA-2025:100262025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python3.12-0:3.12.11-1.el8_10RHSA-2025:100312025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python3-0:3.6.8-70.el8_10RHSA-2025:101282025-07-01T00:00:00Z
Red Hat Enterprise Linux 8python39:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python39-devel:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python39:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python39-devel:3.9-8100020251126112422.d47b87a4RHSA-2025:235302025-12-18T00:00:00Z
Red Hat Enterprise Linux 8python3-0:3.6.8-70.el8_10RHSA-2025:101282025-07-01T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportpython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-Onpython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicepython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionspython3-0:3.6.8-47.el8_6.8RHSA-2025:104842025-07-07T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Support Long-Life Add-Onpython3-0:3.6.8-51.el8_8.10RHSA-2025:106022025-07-08T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicepython3-0:3.6.8-51.el8_8.10RHSA-2025:106022025-07-08T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionspython3-0:3.6.8-51.el8_8.10RHSA-2025:106022025-07-08T00:00:00Z
Red Hat Enterprise Linux 9python3.9-0:3.9.21-2.el9_6.1RHSA-2025:101362025-07-01T00:00:00Z
Red Hat Enterprise Linux 9python3.11-0:3.11.11-2.el9_6.1RHSA-2025:101482025-07-01T00:00:00Z
Red Hat Enterprise Linux 9python3.12-0:3.12.9-1.el9_6.1RHSA-2025:101892025-07-02T00:00:00Z
Red Hat Enterprise Linux 9python3.9-0:3.9.21-2.el9_6.1RHSA-2025:101362025-07-01T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpython3.12-0:3.12.1-4.el9_4.6RHSA-2025:100282025-07-01T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpython3.9-0:3.9.18-3.el9_4.8RHSA-2025:103992025-07-07T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportpython3.11-0:3.11.7-1.el9_4.8RHSA-2025:99182025-06-30T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1752066672RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1752065732RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-controller-rhel8:7.13.5-4.1752065732RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752065737RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752065731RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-operator-bundle:7.13.5-25RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752065736RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-rhel8-operator:7.13.5-2.1752065733RHSA-2025:113862025-07-17T00:00:00Z
RHEL-8 based Middleware Containersrhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752065755RHSA-2025:113862025-07-17T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-management-console-rhel8:1.36.0-9RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-rhel8-operator:1.36.0-18RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11RHSA-2026:09342026-01-22T00:00:00Z
RHOSS-1.36-RHEL-8openshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7RHSA-2026:09342026-01-22T00:00:00Z
cert-manager operator for Red Hat OpenShift 1.16cert-manager/jetstack-cert-manager-rhel9:v1.16.5-1760515757RHSA-2025:182192025-10-16T00:00:00Z
Red Hat Discovery 2discovery/discovery-server-rhel9:2.0.1-1754478727RHSA-2025:132672025-08-06T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Apply commands

bash fix
Apply RHSA-2025:10140 for Red Hat Enterprise Linux 10
yum update -y python3
# or:
dnf upgrade -y python3

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat OpenShift Container Platform 4Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed python-unversioned-command-3.9.21-2.el9_6.1.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
forky Fixed 0
bullseye Fixed 0
bookworm Fixed 0
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.