Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:58953: Important: python-urwid security update

A vulnerability (CVE-2026-9323, CVSS 8.1 HIGH) in the python-urwid library involves predictable session IDs, which can lead to remote code execution and information disclosure. The security update is rated Important and applies to Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related Extended Life Cycle variants. Affected systems should be updated using the packages and instructions provided in the Red Hat advisory.
Read Full Article →

Red Hat Product Errata RHSA-2026:58953 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:58953 - Security Advisory Overview Updated Packages Synopsis Important: python-urwid security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for python-urwid is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): urwid: Urwid: Predictable session IDs lead to remote code execution and information disclosure (CVE-2026-9323) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2502072 - CVE-2026-9323 urwid: Urwid: Predictable session IDs lead to remote code execution and information disclosure CVEs CVE-2026-9323 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df x86_64 python-urwid-debugsource-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: e1594008844a9d167c12653133b2aa426e5e9f4dd91ebe22872479148625ff18 python3-urwid-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: d41395ca493d78c71ece22b33d517637fbb68575852865f21755505aed650360 python3-urwid-debuginfo-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: 3473c0017ee2cd0db805d5533e3ee8c153e8f5a57d7941b2dbaf0ab3827a5051 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df ppc64le python-urwid-debugsource-2.1.2-4.el9_4.1.ppc64le.rpm SHA-256: d0e75a3740f3071f8b7aea359bcc0e87a8fd5680d07844d69d868b219f14dda3 python3-urwid-2.1.2-4.el9_4.1.ppc64le.rpm SHA-256: d428d80496d30388ff057db9544e19e51b2ad015bc20a7dba24ab2b2749eca92 python3-urwid-debuginfo-2.1.2-4.el9_4.1.ppc64le.rpm SHA-256: 2cbc1e6fb4399a1625d3be6409d69a5cba079104a41bedb5cd0cc828182b6f51 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df x86_64 python-urwid-debugsource-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: e1594008844a9d167c12653133b2aa426e5e9f4dd91ebe22872479148625ff18 python3-urwid-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: d41395ca493d78c71ece22b33d517637fbb68575852865f21755505aed650360 python3-urwid-debuginfo-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: 3473c0017ee2cd0db805d5533e3ee8c153e8f5a57d7941b2dbaf0ab3827a5051 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df aarch64 python-urwid-debugsource-2.1.2-4.el9_4.1.aarch64.rpm SHA-256: a2cd65d3d277cd19e5514e742bbb522f54bc4ec02d2814a0fa5bd8443d0e48fd python3-urwid-2.1.2-4.el9_4.1.aarch64.rpm SHA-256: fc31c65eb178c6e0c2a52726c257facc847a0619ae7c035b2df75fde603f5d69 python3-urwid-debuginfo-2.1.2-4.el9_4.1.aarch64.rpm SHA-256: ee36e0b9a2255d37aa72ca80f1ad6d40c45dcc683fb89762ea38a5bdc74be7d8 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df s390x python-urwid-debugsource-2.1.2-4.el9_4.1.s390x.rpm SHA-256: 3e867e5b0940a826ca582527b3e68ef0f8059c81b561592b9fd71ddb2b248ec5 python3-urwid-2.1.2-4.el9_4.1.s390x.rpm SHA-256: d18eff7b2285b55aba43334170bac44ff99c8710f9333d9fccf2e4076ce3a8ef python3-urwid-debuginfo-2.1.2-4.el9_4.1.s390x.rpm SHA-256: 0ac2699d11b4a1f14e7510edafe9ee01fa589f2560ddd9859adefa0f3c1a8e1e Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df x86_64 python-urwid-debugsource-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: e1594008844a9d167c12653133b2aa426e5e9f4dd91ebe22872479148625ff18 python3-urwid-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: d41395ca493d78c71ece22b33d517637fbb68575852865f21755505aed650360 python3-urwid-debuginfo-2.1.2-4.el9_4.1.x86_64.rpm SHA-256: 3473c0017ee2cd0db805d5533e3ee8c153e8f5a57d7941b2dbaf0ab3827a5051 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df aarch64 python-urwid-debugsource-2.1.2-4.el9_4.1.aarch64.rpm SHA-256: a2cd65d3d277cd19e5514e742bbb522f54bc4ec02d2814a0fa5bd8443d0e48fd python3-urwid-2.1.2-4.el9_4.1.aarch64.rpm SHA-256: fc31c65eb178c6e0c2a52726c257facc847a0619ae7c035b2df75fde603f5d69 python3-urwid-debuginfo-2.1.2-4.el9_4.1.aarch64.rpm SHA-256: ee36e0b9a2255d37aa72ca80f1ad6d40c45dcc683fb89762ea38a5bdc74be7d8 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df ppc64le python-urwid-debugsource-2.1.2-4.el9_4.1.ppc64le.rpm SHA-256: d0e75a3740f3071f8b7aea359bcc0e87a8fd5680d07844d69d868b219f14dda3 python3-urwid-2.1.2-4.el9_4.1.ppc64le.rpm SHA-256: d428d80496d30388ff057db9544e19e51b2ad015bc20a7dba24ab2b2749eca92 python3-urwid-debuginfo-2.1.2-4.el9_4.1.ppc64le.rpm SHA-256: 2cbc1e6fb4399a1625d3be6409d69a5cba079104a41bedb5cd0cc828182b6f51 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 SRPM python-urwid-2.1.2-4.el9_4.1.src.rpm SHA-256: 917891876893e56b8794147513c8b1d8eebe335079053cc232a424160f4308df s390x python-urwid-debugsource-2.1.2-4.el9_4.1.s390x.rpm SHA-256: 3e867e5b0940a826ca582527b3e68ef0f8059c81b561592b9fd71ddb2b248ec5 python3-urwid-2.1.2-4.el9_4.1.s390x.rpm SHA-256: d18eff7b2285b55aba43334170bac44ff99c8710f9333d9fccf2e4076ce3a8ef python3-urwid-debuginfo-2.1.2-4.el9_4.1.s390x.rpm SHA-256: 0ac2699d11b4a1f14e7510edafe9ee01fa589f2560ddd9859adefa0f3c1a8e1e The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article