The vendor explicitly identifies these products as affected by this CVE.
- python-unversioned-command as a component of Red Hat Enterprise Linux 10
- python3 as a component of Red Hat Enterprise Linux 10
- python3-debug as a component of Red Hat Enterprise Linux 10
- python3-devel as a component of Red Hat Enterprise Linux 10
- python3-idle as a component of Red Hat Enterprise Linux 10
- python3-libs as a component of Red Hat Enterprise Linux 10
- python3-test as a component of Red Hat Enterprise Linux 10
- python3-tkinter as a component of Red Hat Enterprise Linux 10
- python3.12.src as a component of Red Hat Enterprise Linux 10
- python3.14 as a component of Red Hat Enterprise Linux 10
- python3.14-debug as a component of Red Hat Enterprise Linux 10
- python3.14-devel as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in Python's `pkgutil.get_data()` function, which is used to retrieve data from packages. This function did not properly validate the `resource` argument, allowing a local attacker to perform path traversal attacks. Path traversal enables an attacker to access files and directories stored outside the intended root directory, potentially leading to information disclosure or unintended file access.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
