SourcelessFileLoader does not use io.open_code()
Published Mar 4, 2026
5.7
MEDIUMCVSS 4.0
EPSS 0.20%
Description
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.
Affected products
-
Affected
- ≥ 0, < 3.10.21
- ≥ 3.11.0, < 3.11.16
- ≥ 3.12.0, < 3.12.14
- ≥ 3.13.0, < 3.13.13
- ≥ 3.14.0, < 3.14.4
- ≥ 3.15.0a1, < 3.15.0a7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Python Software Foundation | CPython | unaffected | Affected
|
No data.
No data.
Red Hat Enterprise Linux 10
python3.12-0:3.12.13-2.el10_2
Fixed · RHSA-2026:19064
Red Hat Enterprise Linux 10
python3.14-0:3.14.4-2.el10_2
Fixed · RHSA-2026:19019
Red Hat Enterprise Linux 8
python3.12-0:3.12.13-2.el8_10
Fixed · RHSA-2026:10950
Red Hat Enterprise Linux 9
python3.12-0:3.12.13-2.el9_8
Fixed · RHSA-2026:19177
Red Hat Enterprise Linux 9
python3.14-0:3.14.4-2.el9_8
Fixed · RHSA-2026:19176
Red Hat Hardened Images
python3-11-main-3.11.15-4.hum1
Fixed · RHSA-2026:8822
Red Hat Hardened Images
python3-12-main-3.12.13-3.hum1
Fixed · RHSA-2026:8824
Red Hat Hardened Images
python3-13-main-3.13.13-1.hum1
Fixed · RHSA-2026:7443
Red Hat Hardened Images
python3-14-main-3.14.4-1.hum1
Fixed · RHSA-2026:7661
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1779798165
Fixed · RHSA-2026:21275
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1779798222
Fixed · RHSA-2026:21275
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Enterprise Linux 6
python
Out of support scope
Red Hat Enterprise Linux 7
python
Out of support scope
Red Hat Enterprise Linux 7
python3
Out of support scope
Red Hat Enterprise Linux 8
python3
Fix deferred
Red Hat Enterprise Linux 8
python3.11
Fix deferred
Red Hat Enterprise Linux 8
python36:3.6/python36
Fix deferred
Red Hat Enterprise Linux 8
python39-devel:3.9/python39
Fix deferred
Red Hat Enterprise Linux 9
python3.11
Fix deferred
Red Hat Enterprise Linux 9
python3.9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | python3.12-0:3.12.13-2.el10_2 | Fixed | RHSA-2026:19064 |
| Red Hat Enterprise Linux 10 | python3.14-0:3.14.4-2.el10_2 | Fixed | RHSA-2026:19019 |
| Red Hat Enterprise Linux 8 | python3.12-0:3.12.13-2.el8_10 | Fixed | RHSA-2026:10950 |
| Red Hat Enterprise Linux 9 | python3.12-0:3.12.13-2.el9_8 | Fixed | RHSA-2026:19177 |
| Red Hat Enterprise Linux 9 | python3.14-0:3.14.4-2.el9_8 | Fixed | RHSA-2026:19176 |
| Red Hat Hardened Images | python3-11-main-3.11.15-4.hum1 | Fixed | RHSA-2026:8822 |
| Red Hat Hardened Images | python3-12-main-3.12.13-3.hum1 | Fixed | RHSA-2026:8824 |
| Red Hat Hardened Images | python3-13-main-3.13.13-1.hum1 | Fixed | RHSA-2026:7443 |
| Red Hat Hardened Images | python3-14-main-3.14.4-1.hum1 | Fixed | RHSA-2026:7661 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1779798165 | Fixed | RHSA-2026:21275 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1779798222 | Fixed | RHSA-2026:21275 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Enterprise Linux 6 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | python3 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | python3.11 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | python39-devel:3.9/python39 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | python3.11 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | python3.9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- http://www.openwall.com/lists/oss-security/2026/03/05/6
- https://access.redhat.com/security/cve/CVE-2026-2297 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2444691 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9498 Advisory
- https://github.com/python/cpython/commit/482d6f8bdba9da3725d272e8bb4a2d25fb6a603e patch
- https://github.com/python/cpython/commit/69ddd9bb2cc4bd69b1565647c18659c6a789ccd9 patch
- https://github.com/python/cpython/commit/876858c9f65d9ab656c7fa639f268ce7856d89dd patch
- https://github.com/python/cpython/commit/a51b1b512de1d56b3714b65628a2eae2b07e535e patch
- https://github.com/python/cpython/commit/c70adad78caeeea33f92f560ecb93331ca11bf66 patch
- https://github.com/python/cpython/commit/e58e9802b9bec5cdbf48fc9bf1da5f4fda482e86 patch
- https://github.com/python/cpython/issues/145506 issue-tracking
- https://github.com/python/cpython/pull/145507 patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-2297
- https://www.cve.org/CVERecord?id=CVE-2026-2297
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data