[CLSA-2026:1784804986] alt-python39: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-23 11:10:11 UTC
Description:
- el10: build _decimal against system libmpdec (BuildRequires mpdecimal-devel, configure --with-system-libmpdec, patch setup.py to link -lmpdec since el10 ships libmpdec.so.3 not .so.2, and _decimal.c uchar->unsigned char for the mpdecimal 2.5 api); the bundled libmpdec fails to compile with -Og under the el10 gcc, which broke the CL10 build - el10: apply 06003 (BIO_eof ASN1 EOF, CPython gh-100372) so test_ssl cadata tests pass with OpenSSL 3.5.x, matching the alpine build (ALTPYTH-611)
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-19.el7.x86_64.rpm
    sha:ebbc43eb1687d91869ba60477c4105d749cffa768ddae8cd351992cdfa0e6b31
  • alt-python39-debug-3.9.23-19.el7.x86_64.rpm
    sha:78b77ac206afd4f08a3c0ce2e6f91bfbbea7149ccc602b562f1b623cd5e35790
  • alt-python39-devel-3.9.23-19.el7.x86_64.rpm
    sha:1ec690ee7b76f9759aa43ac73992a194c628bb17fd2dddaa018b0d98cc3eefd4
  • alt-python39-idle-3.9.23-19.el7.x86_64.rpm
    sha:97ec01486a0d97690e10f807906394d68589a8424eefbfbb471baf1fd8dffc86
  • alt-python39-libs-3.9.23-19.el7.x86_64.rpm
    sha:537cf5b9943188cfaac3247928f61f4acd8d4d4c6c450dcaf9e02e3f7d7e242b
  • alt-python39-test-3.9.23-19.el7.x86_64.rpm
    sha:dec06fdd6ea6751c403307456e73591c80ec5e9f8c04355d8e31b6a97ce04356
  • alt-python39-tkinter-3.9.23-19.el7.x86_64.rpm
    sha:14bd5d05dd8a52d0daeee9e7f932250b28ada4b8a960d9e5559bdbd69ec78a38
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.