Release date:
2026-07-23 17:22:01 UTC
Description:
* SECURITY UPDATE: webbrowser argument injection via action-token substitution
- debian/patches/CVE-2026-4786.patch: validate expanded command (bypass of CVE-2026-4519)
- CVE-2026-4786
* SECURITY UPDATE: use-after-free in bz2/lzma decompressor reuse after MemoryError
- debian/patches/CVE-2026-6100.patch: clear next_in on the decompress error path
- CVE-2026-6100
* SECURITY UPDATE: insufficient entropy for Expat hash-flooding protection
- debian/patches/CVE-2026-7210.patch: use XML_SetHashSalt16Bytes 16-byte entropy
- CVE-2026-7210
* SECURITY UPDATE: insufficient entropy in bundled Expat (libexpat) hash-flooding protection
- debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the bundled expat so the CVE-2026-7210 16-byte salt path is not inert on bundled-expat builds
- CVE-2026-41080
* SECURITY UPDATE: stack buffer overflow via bz2 decompressor reuse after error
- debian/patches/CVE-2026-9669.patch: refuse reuse after a previous error
- CVE-2026-9669
Updated packages:
-
alt-python310_3.10.20-4_amd64.deb
sha:2834da766fcf0e2ba6d6b89f370034ff060d234e
-
alt-python310-debug_3.10.20-4_amd64.deb
sha:4c3aaf0428044f67d05e7aa8b289b4df2cc2fbd8
-
alt-python310-devel_3.10.20-4_amd64.deb
sha:4bd5b2ff3d15ecdb94041c9545d596e2b01c4575
-
alt-python310-idle_3.10.20-4_amd64.deb
sha:893b202582a6c91d7e6f865f6d09fa3abbd20ace
-
alt-python310-libs_3.10.20-4_amd64.deb
sha:6d538880100874f50b55c8dfc0ec8fec605a28fd
-
alt-python310-test_3.10.20-4_amd64.deb
sha:f1a180bc734d4c663d99dfdb5500f79c2bf06b37
-
alt-python310-tkinter_3.10.20-4_amd64.deb
sha:bc7b38202fcaec874d1742fa286d3a5be29cfda1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.