[CLSA-2026:1790159427] Fix CVE(s): CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 10:30:39 UTC
Description:
* ALTPYTH-616: Update to 3.10.21 * Drop CVE backports included in upstream 3.10.21: CVE-2026-3644, CVE-2026-4224, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-9669, CVE-2026-41080, CVE-2026-15308, CVE-2025-13462, CVE-2026-8328, CVE-2026-7774, CVE-2026-1502, CVE-2026-3276, CVE-2026-0864, CVE-2026-11972, CVE-2026-11940, CVE-2026-6879 * debian/patches/CVE-2026-7210.patch: re-anchor the Include/pyexpat.h hunk onto the 3.10.21 PyExpat_CAPI layout, which inserted the SetBillionLaughsAttackProtection* members before the end-of-struct sentinel, so the patch applies with --fuzz=0 instead of relying on the builder's --fuzz=2. No functional change: the new SetHashSalt16Bytes member still lands last in the struct (the expat >= 2.4.0 runtime requirement added on the RPM side is not needed here -- Debian/Ubuntu builds use --without-system-expat)
CVEs fixed:
Updated packages:
  • alt-python310_3.10.21-1_amd64.deb
    sha:0b89a78f337ea24ec203a62cfc4486d3fda0e9bd
  • alt-python310-debug_3.10.21-1_amd64.deb
    sha:59d3465dd762ef018fdf654af86a02f168371032
  • alt-python310-devel_3.10.21-1_amd64.deb
    sha:247ccb606e4c6e8fd49f5b0b22be22418c79035c
  • alt-python310-idle_3.10.21-1_amd64.deb
    sha:804298b98bcb4cbd441dbae255df8aa8cc26c9b4
  • alt-python310-libs_3.10.21-1_amd64.deb
    sha:d8b9ce47c0366ded27a802374a440f831753c66f
  • alt-python310-test_3.10.21-1_amd64.deb
    sha:0298d4a55c59db6ea32da6332b85f1ce92923681
  • alt-python310-tkinter_3.10.21-1_amd64.deb
    sha:7e612305cae4707b66646fc81450069e79cef589
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.