Skip to content
Fedora 42 python3.12 Critical Arbitrary Code Execution Vuln 2026

Fedora 42 python3.12 Critical Arbitrary Code Execution Vuln 2026

Linuxsecurity LinuxSecurity Advisories April 20, 2026

Python 3.12 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.12 package provides the "python3.12" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.12-libs package, which should be installed automatically along with python3.12. The remaining parts of the Python standard library are broken out into the python3.12-tkinter and python3.12-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.12-docs package. Packages containing additional libraries for Python are generally named with the "python3.12-" prefix. Update Information : Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224

Python 3.12 is an accessible, high-level, dynamically typed, interpreted

programming language, designed with an emphasis on code readability.

It includes an extensive standard library, and has a vast ecosystem of

third-party libraries.

The python3.12 package provides the "python3.12" executable: the reference

interpreter for the Python language, version 3.

The majority of its standard library is provided in the python3.12-libs package,

which should be installed automatically along with python3.12.

The remaining parts of the Python standard library are broken out into the

python3.12-tkinter and python3.12-test packages, which may need to be installed

Documentation for Python is provided in the python3.12-docs package.

Packages containing additional libraries for Python are generally named with

the "python3.12-" prefix.

Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224

* Thu Apr 16 2026 Charalampos Stratakis - 3.12.13-3 - Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224 Resolves: rhbz#2444705, rhbz#2448189, rhbz#2448205, rhbz#2457942, rhbz#2458014, rhbz#2458222

* Thu Apr 16 2026 Charalampos Stratakis - 3.12.13-3 - Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224 Resolves: rhbz#2444705, rhbz#2448189, rhbz#2448205, rhbz#2457942, rhbz#2458014, rhbz#2458222

[ 1 ] Bug #2444705 - CVE-2026-2297 python3.12: CPython: Logging Bypass in Legacy .pyc File Handling [fedora-all] [ 2 ] Bug #2448189 - CVE-2026-3644 python3.12: Incomplete control character validation in http.cookies [fedora-all] [ 3 ] Bug #2448205 - CVE-2026-4224 python3.12: Stack overflow parsing XML with deeply nested DTD content models [fedora-all] [ 4 ] Bug #2457942 - CVE-2026-1502 python3.12: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all] [ 5 ] Bug #2458014 - CVE-2026-6100 python3.12: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules [fedora-all] [ 6 ] Bug #2458222 - CVE-2026-4786... Read the Full Advisory

[ 1 ] Bug #2444705 - CVE-2026-2297 python3.12: CPython: Logging Bypass in Legacy .pyc File Handling [fedora-all] [ 2 ] Bug #2448189 - CVE-2026-3644 python3.12: Incomplete control character validation in http.cookies [fedora-all] [ 3 ] Bug #2448205 - CVE-2026-4224 python3.12: Stack overflow parsing XML with deeply nested DTD content models [fedora-all] [ 4 ] Bug #2457942 - CVE-2026-1502 python3.12: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all] [ 5 ] Bug #2458014 - CVE-2026-6100 python3.12: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules [fedora-all] [ 6 ] Bug #2458222 - CVE-2026-4786...

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-30fbc5a8b2' at the command line. For more information, refer to the dnf documentation available at

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-30fbc5a8b2' at the command line. For more information, refer to the dnf documentation available at