[CLSA-2026:1784826542] Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-23 17:09:57 UTC
Description:
* SECURITY UPDATE: webbrowser.open() dash-prefix check bypass via the action token - debian/patches/CVE-2026-4786.patch: validate the action-expanded URL and reorder the action/URL substitution so a URL containing the action token cannot expand into a dash-prefixed browser flag (CVE-2026-4519 bypass). - CVE-2026-4786 * SECURITY UPDATE: dangling input pointer (UAF) in bz2/lzma decompressors - debian/patches/CVE-2026-6100.patch: clear next_in on the MemoryError error path in _bz2/_lzma decompress() so a reused decompressor cannot read or write through a stale pointer to the released input buffer. - CVE-2026-6100 * SECURITY UPDATE: insufficient Expat hash-flooding entropy - debian/patches/CVE-2026-7210.patch: seed Expat with 16 bytes of entropy via XML_SetHashSalt16Bytes when libexpat exposes it (weak symbol), falling back to the legacy 8-byte salt otherwise. - debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the BUNDLED expat (applied on ubuntu16.04 only; el7 on the RPM side) so the 16-byte salt path above is not inert; other platforms link system expat. - CVE-2026-7210 * SECURITY UPDATE: bz2.BZ2Decompressor reuse after error (stack overflow) - debian/patches/CVE-2026-9669.patch: record the libbz2 error and raise ValueError on any subsequent decompress() call instead of re-entering libbz2 on an inconsistent stream (CWE-121). - CVE-2026-9669
Updated packages:
  • alt-python311_3.11.15-3_amd64.deb
    sha:1a4920edd9f99042fa0764208634e0af63f72aa8
  • alt-python311-debug_3.11.15-3_amd64.deb
    sha:aa9cae63e1b75ba14db6da64dcbe20179575eb73
  • alt-python311-devel_3.11.15-3_amd64.deb
    sha:1fbb16279ff2c000a30f8c41b53931072e521ae5
  • alt-python311-idle_3.11.15-3_amd64.deb
    sha:4debd69fb9552ef012ecdfbc4908c527ae4dd213
  • alt-python311-libs_3.11.15-3_amd64.deb
    sha:66aeee04e4f01772f18a35a6b23289b5c97e101d
  • alt-python311-test_3.11.15-3_amd64.deb
    sha:af47b9337daa9de3b91757c22fc6cf58f32a9f9c
  • alt-python311-tkinter_3.11.15-3_amd64.deb
    sha:a888694d0c375c6d754c72fb454d0dc8106ef0d5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.