[CLSA-2026:1790159252] alt-python310: Fix of CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 10:27:44 UTC
Description:
- ALTPYTH-616: Update to 3.10.21 - Drop 06003-ssl-use-bio_eof-for-asn1-cadata-eof.patch, included in upstream 3.10.21 - Drop CVE backports included in upstream 3.10.21: CVE-2026-3644, CVE-2026-4224, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-9669, CVE-2026-41080, CVE-2026-15308, CVE-2025-13462, CVE-2026-8328, CVE-2026-7774, CVE-2026-1502, CVE-2026-3276, CVE-2026-0864, CVE-2026-11972, CVE-2026-11940, CVE-2026-6879 - Require expat >= 2.4.0 on rhel > 7: 3.10.21 calls XML_SetBillionLaughsAttackProtectionActivationThreshold and ...MaximumAmplification, which are required (non-weak) symbols in pyexpat. libexpat has no symbol versioning, so RPM records only libexpat.so.1()(64bit) and cannot derive the floor; on an older expat the package installs and then fails at import with "undefined symbol". CL7 keeps the bundled expat - Re-anchor the Include/pyexpat.h hunk of CVE-2026-7210.patch onto the 3.10.21 PyExpat_CAPI layout (3.10.21 inserted the SetBillionLaughsAttackProtection* members before the end-of-struct sentinel) so it applies with --fuzz=0
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-1.el10.x86_64.rpm
    sha:5eae9a85edf2c8cda35526721794014f9f9424598b7ef66d94cdea2b4ff1bf07
  • alt-python310-debug-3.10.21-1.el10.x86_64.rpm
    sha:ab658f483ce1acd2da2a8d44bfe92cf4f7ef9c018adb82e6f910c8f80b6ea8a4
  • alt-python310-devel-3.10.21-1.el10.x86_64.rpm
    sha:bb223db66419b2d4654b291c2982b8e1e4e159fe99f2fc94c8e6119f90ff7cd3
  • alt-python310-idle-3.10.21-1.el10.x86_64.rpm
    sha:d9e71f01fc7778d28625615da5026bbe18e657ba69849c89673289c1c6ca3f6e
  • alt-python310-libs-3.10.21-1.el10.x86_64.rpm
    sha:bc8c2d8b17e2459c33a5e8bbba3c2ee9af96f7f0b869bcc30b226688dc383bfa
  • alt-python310-test-3.10.21-1.el10.x86_64.rpm
    sha:d3e5cb34a54c07ffaf07fe2a7afc619e0974f80cd1c57546816220a99c49f064
  • alt-python310-tkinter-3.10.21-1.el10.x86_64.rpm
    sha:af5e5c8d2b7f3a90aafe103843470864ea075a2200d69819c021482e928e6fd8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.