Release date:
2026-07-23 16:22:11 UTC
Description:
- CVE-2026-4786: reject action-token-expanded dash-prefixed args in webbrowser.open() (CVE-2026-4519 bypass)
- CVE-2026-6100: fix dangling next_in pointer (UAF) in bz2/lzma decompressors after MemoryError on reuse
- CVE-2026-7210: use XML_SetHashSalt16Bytes 16-byte entropy for Expat hash-flooding protection when available
- CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (ubuntu16.04 / el7; other platforms link system expat) so the CVE-2026-7210 16-byte salt path is not inert
- CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression error (stack buffer overflow)
Updated packages:
-
alt-python311-3.11.15-3.el9.x86_64.rpm
sha:c9fc92e1d31fec7afef0a290379f965d3b5bd0dbdc556604944c500d60d1e59b
-
alt-python311-debug-3.11.15-3.el9.x86_64.rpm
sha:83dda00e3cdf6898d01bc5249caf4cb2a7e176ccd93387171976c5772688cde6
-
alt-python311-devel-3.11.15-3.el9.x86_64.rpm
sha:8bed985258bcaf61566a8296576795306e9ec3aff3c009549e1d517afbf3dd75
-
alt-python311-idle-3.11.15-3.el9.x86_64.rpm
sha:ece74f188d005a9f2d3c59be2662e2188ead2d126b5167326aae937154686a50
-
alt-python311-libs-3.11.15-3.el9.x86_64.rpm
sha:ee39db9160dd0e2ed253f9ec9aaa82462793d96b281832d85f7687984b5f9615
-
alt-python311-test-3.11.15-3.el9.x86_64.rpm
sha:e7bee4eefeceea1b66a2f6df03ffe8796e3bd8e1a8e810dd4b287cb334d035df
-
alt-python311-tkinter-3.11.15-3.el9.x86_64.rpm
sha:6055927b768e9e86aaa1261affbd871990b7dd168d1d081699b74b332679b1f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.