Red Hat Product Errata RHSA-2026:58928 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:58928 - Security Advisory Overview Updated Packages Synopsis Important: python3.14 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for python3.14 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory (CVE-2026-11940) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2491848 - CVE-2026-11940 python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory CVEs CVE-2026-11940 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 x86_64 python3.14-3.14.7-2.el10_2.x86_64.rpm SHA-256: cf60defda620323fbfc830e39343a6ef22d44dde6dbe63bde5d0c064ebe2a65c python3.14-debuginfo-3.14.7-2.el10_2.x86_64.rpm SHA-256: 82912832f526ae00248d76895158b6e3e7efee2736f657eaceca89b7b2ab3b14 python3.14-debugsource-3.14.7-2.el10_2.x86_64.rpm SHA-256: 6d22e539bde067d672e5053629474dbfa87d359c4086fef9eeebd0b1255a1662 python3.14-devel-3.14.7-2.el10_2.x86_64.rpm SHA-256: b2c1b4788bdd6c2fab9c0728e0241620e3ce37a069e48d79a0396a74be409d7c python3.14-libs-3.14.7-2.el10_2.x86_64.rpm SHA-256: 6b5a4e98d53f2f434d17df505500bf33eb526997f2c4950d1fe2720ee379245c python3.14-tkinter-3.14.7-2.el10_2.x86_64.rpm SHA-256: 319723f2e44a9e5a06404bac571f653250cca2024dca85c033715acd9782d2f9 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 x86_64 python3.14-3.14.7-2.el10_2.x86_64.rpm SHA-256: cf60defda620323fbfc830e39343a6ef22d44dde6dbe63bde5d0c064ebe2a65c python3.14-debuginfo-3.14.7-2.el10_2.x86_64.rpm SHA-256: 82912832f526ae00248d76895158b6e3e7efee2736f657eaceca89b7b2ab3b14 python3.14-debugsource-3.14.7-2.el10_2.x86_64.rpm SHA-256: 6d22e539bde067d672e5053629474dbfa87d359c4086fef9eeebd0b1255a1662 python3.14-devel-3.14.7-2.el10_2.x86_64.rpm SHA-256: b2c1b4788bdd6c2fab9c0728e0241620e3ce37a069e48d79a0396a74be409d7c python3.14-libs-3.14.7-2.el10_2.x86_64.rpm SHA-256: 6b5a4e98d53f2f434d17df505500bf33eb526997f2c4950d1fe2720ee379245c python3.14-tkinter-3.14.7-2.el10_2.x86_64.rpm SHA-256: 319723f2e44a9e5a06404bac571f653250cca2024dca85c033715acd9782d2f9 Red Hat Enterprise Linux for IBM z Systems 10 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 s390x python3.14-3.14.7-2.el10_2.s390x.rpm SHA-256: 47eefab3ea5a7b06cdc512011369e6fa3047adc43ad3514bfa688a0387764946 python3.14-debuginfo-3.14.7-2.el10_2.s390x.rpm SHA-256: 229950c1602f38ab51ca75ed043dba33ca751b14af21226fe50a91c4ca218c19 python3.14-debugsource-3.14.7-2.el10_2.s390x.rpm SHA-256: 33d395accfc3d1b82eb4680c73790d28d6316abe9a9eb3851c037c7fff48d6fb python3.14-devel-3.14.7-2.el10_2.s390x.rpm SHA-256: 120d40f4befb1ab15c99a5e1b3d5f6a2b7c593bf2ab9631b31394bcc76077fc1 python3.14-libs-3.14.7-2.el10_2.s390x.rpm SHA-256: 2d435bccb6e0aa555e0d3be0483623d0d59b1d80c9e3937da0eb1832e52d40bd python3.14-tkinter-3.14.7-2.el10_2.s390x.rpm SHA-256: 988d7bd6400dbf6ddac424808f208382cd68171fb79f55ea2e7edbcef0bc1c44 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 s390x python3.14-3.14.7-2.el10_2.s390x.rpm SHA-256: 47eefab3ea5a7b06cdc512011369e6fa3047adc43ad3514bfa688a0387764946 python3.14-debuginfo-3.14.7-2.el10_2.s390x.rpm SHA-256: 229950c1602f38ab51ca75ed043dba33ca751b14af21226fe50a91c4ca218c19 python3.14-debugsource-3.14.7-2.el10_2.s390x.rpm SHA-256: 33d395accfc3d1b82eb4680c73790d28d6316abe9a9eb3851c037c7fff48d6fb python3.14-devel-3.14.7-2.el10_2.s390x.rpm SHA-256: 120d40f4befb1ab15c99a5e1b3d5f6a2b7c593bf2ab9631b31394bcc76077fc1 python3.14-libs-3.14.7-2.el10_2.s390x.rpm SHA-256: 2d435bccb6e0aa555e0d3be0483623d0d59b1d80c9e3937da0eb1832e52d40bd python3.14-tkinter-3.14.7-2.el10_2.s390x.rpm SHA-256: 988d7bd6400dbf6ddac424808f208382cd68171fb79f55ea2e7edbcef0bc1c44 Red Hat Enterprise Linux for Power, little endian 10 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 ppc64le python3.14-3.14.7-2.el10_2.ppc64le.rpm SHA-256: b9b82a10a36024fec549fc619aec3829b0dfb6ad88d509a8f749be57c6f34a03 python3.14-debuginfo-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 3c5fccaa35d33814a406d25a52442cd01fb3a77cb294aa9f48a8ecc9cec2aba1 python3.14-debugsource-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 706b21f22330384a2990187660a457d977d98b970d23fa11d6ad646b32e1988c python3.14-devel-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 70b030243034b77ac2f26991d5bd9930432f5e679da74a17b2e11ee308ef9287 python3.14-libs-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 078889279434691b62feaeab6fa510ecef07327792949eb7fa5bd15b50f72707 python3.14-tkinter-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 2902488ab0fe936d68ce47e05f7d9a9129c3dbcd461e1880f1bda74e1708ac58 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 ppc64le python3.14-3.14.7-2.el10_2.ppc64le.rpm SHA-256: b9b82a10a36024fec549fc619aec3829b0dfb6ad88d509a8f749be57c6f34a03 python3.14-debuginfo-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 3c5fccaa35d33814a406d25a52442cd01fb3a77cb294aa9f48a8ecc9cec2aba1 python3.14-debugsource-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 706b21f22330384a2990187660a457d977d98b970d23fa11d6ad646b32e1988c python3.14-devel-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 70b030243034b77ac2f26991d5bd9930432f5e679da74a17b2e11ee308ef9287 python3.14-libs-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 078889279434691b62feaeab6fa510ecef07327792949eb7fa5bd15b50f72707 python3.14-tkinter-3.14.7-2.el10_2.ppc64le.rpm SHA-256: 2902488ab0fe936d68ce47e05f7d9a9129c3dbcd461e1880f1bda74e1708ac58 Red Hat Enterprise Linux for ARM 64 10 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 aarch64 python3.14-3.14.7-2.el10_2.aarch64.rpm SHA-256: 0d5568e605088520886fd7ccd9dd57c3b7560e1f87d34cee934fb15dd585ec07 python3.14-debuginfo-3.14.7-2.el10_2.aarch64.rpm SHA-256: 2338d8a39e98d624983e124bb0aaae444afdcfbdb05c23b35f32d5e7a6767631 python3.14-debugsource-3.14.7-2.el10_2.aarch64.rpm SHA-256: cdfa6d3e5df122fce432724178b178d6a039fe938dc28e0226c3960ebe9761c1 python3.14-devel-3.14.7-2.el10_2.aarch64.rpm SHA-256: 89553e8c5000830b7e5019f3e9725b7adc8a45c56bb4d01986080651cc9d1836 python3.14-libs-3.14.7-2.el10_2.aarch64.rpm SHA-256: 2f2b292d7231c1fc7451d33828017edc63899f841d4577022b2f0da2f6e2ab7c python3.14-tkinter-3.14.7-2.el10_2.aarch64.rpm SHA-256: c9fc03fc12174ed0fdfaef3713deda60cb7c546a715b31c21e0af56e2e73a586 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM python3.14-3.14.7-2.el10_2.src.rpm SHA-256: c8877566b233be1895f5e72bd80296852733d0142377dca887d75d0159bf48f3 aarch64 python3.14-3.14.7
A directory traversal vulnerability (CVE-2026-11940) in CPython's tarfile module allows attackers to bypass extraction filters and write files outside the intended destination directory. The Red Hat advisory rates this update as Important and affects the python3.14 package for Red Hat Enterprise Linux 10. Systems should be patched according to the provided Red Hat solution article.