AIX

AIX

Connect with fellow AIX users and experts to gain knowledge, share insights, and solve problems.


#Power
#Power
#Operatingsystems
#Servers
 View Only
  • 1.  Python 3.11 installation and related rpm vulnerability

    Posted 12/26/25 10:32 AM

    Regarding the recent configuration of DNF and the installation of Python 3.11. During these processes, a significant number of RPM packages were installed. Could you please confirm if this is necessary or if there is an alternative recommended method to achieve these installations?

    Our servers are subject to frequent scans, and if any package has vulnerabilities associated with its version, we need to take immediate action. The more packages we have, the higher the probability of vulnerabilities and the need for additional fixes. Below is the list of packages that were installed as part of the DNF and Python 3.11 installations:

    #rpm -qa --last|grep -i Dec

    1765781383 python3.11-3.11.9-1.ppc Mon Dec 15 10:49:43 +04 2025

    1765781364 sqlite-3.45.3-1.ppc Mon Dec 15 10:49:24 +04 2025

    1765781364 gdbm-1.23-1.ppc Mon Dec 15 10:49:24 +04 2025

    1765781364 expat-2.6.3-1.ppc Mon Dec 15 10:49:24 +04 2025

    1765781363 readline-8.2-1.ppc Mon Dec 15 10:49:23 +04 2025

    1765781363 libunistring-1.1-1.ppc Mon Dec 15 10:49:23 +04 2025

    1765781363 info-7.0.2-1.ppc Mon Dec 15 10:49:23 +04 2025

    1765781362 gettext-0.21-2.ppc Mon Dec 15 10:49:22 +04 2025

    1765781361 libxml2-2.12.9-1.ppc Mon Dec 15 10:49:21 +04 2025

    1765781361 libiconv-1.17-1.ppc Mon Dec 15 10:49:21 +04 2025

    1765781360 glib2-2.81.0-1.ppc Mon Dec 15 10:49:20 +04 2025

    1765781358 xz-libs-5.4.3-1.ppc Mon Dec 15 10:49:18 +04 2025

    1765781358 pcre2-10.40-1.ppc Mon Dec 15 10:49:18 +04 2025

    1765781358 ncurses-6.4-1.ppc Mon Dec 15 10:49:18 +04 2025

    1765781358 libtextstyle-0.21-2.ppc Mon Dec 15 10:49:18 +04 2025

    1765781358 libgomp10-10.3.0-6.ppc Mon Dec 15 10:49:18 +04 2025

    1765781358 libgomp-10-2.ppc Mon Dec 15 10:49:18 +04 2025

    1765781358 libffi-3.4.4-2.ppc Mon Dec 15 10:49:18 +04 2025

    1765781358 bzip2-1.0.8-2.ppc Mon Dec 15 10:49:18 +04 2025

    1765781351 libstdc++10-10.3.0-6.ppc Mon Dec 15 10:49:11 +04 2025

    1765781351 libstdc++-10-2.ppc Mon Dec 15 10:49:11 +04 2025

    1765781349 zlib-1.2.13-1.ppc Mon Dec 15 10:49:09 +04 2025

    1765781349 libgcc10-10.3.0-6.ppc Mon Dec 15 10:49:09 +04 2025

    1765781349 libgcc-10-2.ppc Mon Dec 15 10:49:09 +04 2025

    1765780988 rpm-python3-4.15.1-32_2.ppc Mon Dec 15 10:43:08 +04 2025

    1765780988 python3-librepo-1.11.0-32_2.ppc Mon Dec 15 10:43:08 +04 2025

    1765780988 python3-libdnf-0.39.1-32_3.ppc Mon Dec 15 10:43:08 +04 2025

    1765780988 python3-hawkey-0.39.1-32_3.ppc Mon Dec 15 10:43:08 +04 2025

    1765780988 python3-gpg-1.13.1-32_3.ppc Mon Dec 15 10:43:08 +04 2025

    1765780988 ca-certificates-2023.2.60-0.ppc Mon Dec 15 10:43:08 +04 2025

    1765780987 yum-4.2.17-32_4.noarch Mon Dec 15 10:43:07 +04 2025

    1765780987 python3.9-libcomps-0.1.15-32_1.ppc Mon Dec 15 10:43:07 +04 2025

    1765780987 python3.9-dnf-4.2.17-32_4.noarch Mon Dec 15 10:43:07 +04 2025

    1765780987 python3-libcomps-0.1.15-32_1.ppc Mon Dec 15 10:43:07 +04 2025

    1765780987 python3-dnf-4.2.17-32_4.noarch Mon Dec 15 10:43:07 +04 2025

    1765780987 p11-kit-tools-0.23.22-0.ppc Mon Dec 15 10:43:07 +04 2025

    1765780987 p11-kit-0.23.22-0.ppc Mon Dec 15 10:43:07 +04 2025

    1765780987 libcomps-0.1.15-32_1.ppc Mon Dec 15 10:43:07 +04 2025

    1765780987 dnf-automatic-4.2.17-32_4.noarch Mon Dec 15 10:43:07 +04 2025

    1765780987 dnf-4.2.17-32_4.noarch Mon Dec 15 10:43:07 +04 2025

    1765780986 python3.9-librepo-1.11.0-32_2.ppc Mon Dec 15 10:43:06 +04 2025

    1765780985 python3.9-hawkey-0.39.1-32_3.ppc Mon Dec 15 10:43:05 +04 2025

    1765780985 python3.9-gpg-1.13.1-32_3.ppc Mon Dec 15 10:43:05 +04 2025

    1765780985 dnf-data-4.2.17-32_4.noarch Mon Dec 15 10:43:05 +04 2025

    1765780984 python3.9-libdnf-0.39.1-32_3.ppc Mon Dec 15 10:43:04 +04 2025

    1765780983 libdnf-0.39.1-32_3.ppc Mon Dec 15 10:43:03 +04 2025

    1765780982 zchunk-libs-1.1.4-32_2.ppc Mon Dec 15 10:43:02 +04 2025

    1765780982 rpm-python3.9-4.15.1-32_2.ppc Mon Dec 15 10:43:02 +04 2025

    1765780982 libsmartcols-2.34-32_1.ppc Mon Dec 15 10:43:02 +04 2025

    1765780982 librepo-1.11.0-32_2.ppc Mon Dec 15 10:43:02 +04 2025

    1765780981 python3-3.9.16-0.ppc Mon Dec 15 10:43:01 +04 2025

    1765780981 libzstd-1.4.4-32_1.ppc Mon Dec 15 10:43:01 +04 2025

    1765780981 libsolv-0.7.9-32_3.ppc Mon Dec 15 10:43:01 +04 2025

    1765780981 libmodulemd-1.5.2-32_2.ppc Mon Dec 15 10:43:01 +04 2025

    1765780980 python3.9-3.9.16-0.ppc Mon Dec 15 10:43:00 +04 2025



    ------------------------------
    AbdulWahab Mohamed
    ------------------------------


  • 2.  RE: Python 3.11 installation and related rpm vulnerability

    Posted 12/26/25 04:14 PM

    The installation of Python 3.11 using DNF/RPM is expected to pull multiple system libraries and dependencies (glibc-related libs, libffi, sqlite, openssl-related components, etc.). These packages are not Python-specific extras, but shared system libraries required for runtime stability, security updates, and integration with the OS package manager.

    However, if the objective is to minimize the system attack surface and reduce RPM vulnerability exposure, there are recommended alternatives:

    Install Python 3.11 from source (./configure --enable-optimizations) under /opt/python3.11, avoiding RPM registration.

    Use pyenv or virtualenv to isolate Python without introducing new system packages.

    Use containers (Podman/Docker) with Python 3.11 images to fully decouple OS packages from application runtime.

    Keep the system Python (3.9) untouched and use Python 3.11 only at the application layer.

    For security-scanned environments, the recommended approach is non-RPM Python installation or containerization, which significantly reduces vulnerability noise while maintaining compliance.



    ------------------------------
    Jorge Prieto
    ------------------------------



  • 3.  RE: Python 3.11 installation and related rpm vulnerability

    Posted 12/27/25 09:26 AM
    On Fri, Dec 26, 2025 at 09:14:25PM +0000, Jorge Prieto via IBM TechXchange Community wrote:
    > The installation of Python 3.11 using DNF/RPM is expected to pull
    > multiple system libraries and dependencies (glibc-related libs,
    > libffi, sqlite, openssl-related components, etc.). These packages
    > are not Python-specific extras, but shared system libraries required
    > for runtime stability, security updates, and integration with the OS
    > package manager.

    Yep, package spam is a problem.

    The correct answer here is to remove Python from AIX 7.3's base
    installation, and don't use DNF/YUM and RPM packages. If you must have
    them, you need a plan or policy to address CVE's with your security
    team.

    > However, if the objective is to minimize the system attack surface
    > and reduce RPM vulnerability exposure, there are recommended
    > alternatives:

    None of your options are reducing attack surface, you're still
    installing everything. You're just saying to not register with the
    package manager, so you have potentially unlisted vulnerabilities. You
    are reducing vulnerability exposure to the security tracking tools,
    not addressing any potential vulnerabilities.

    Containers also don't fix the problem of vulnerabilities, it's just
    another way to hide them from the package manager. Containers often
    contain more superfluous code, and are infrequently updated so they
    can have more CVEs.

    TLDR: You're recommending lying to cybersecurity, because security is
    inconvenient. If I were your Cybersecurity team, I'd be furious.


    ------------------------------------------------------------------
    Russell Adams Russell.Adams@AdamsSystems.nl
    Principal Consultant Adams Systems Consultancy
    https://adamssystems.nl/