[CLSA-2026:1784820763] Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-23 15:33:30 UTC
Description:
* SECURITY UPDATE: webbrowser.open() dash-prefix check bypass via the action token - debian/patches/CVE-2026-4786.patch: validate the action-expanded URL and reorder the action/URL substitution so a URL containing the action token cannot expand into a dash-prefixed browser flag (CVE-2026-4519 bypass). - CVE-2026-4786 * SECURITY UPDATE: dangling input pointer (UAF) in bz2/lzma decompressors - debian/patches/CVE-2026-6100.patch: clear next_in on the MemoryError error path in _bz2/_lzma decompress() so a reused decompressor cannot read or write through a stale pointer to the released input buffer. - CVE-2026-6100 * SECURITY UPDATE: insufficient Expat hash-flooding entropy - debian/patches/CVE-2026-7210.patch: seed Expat with 16 bytes of entropy via XML_SetHashSalt16Bytes when libexpat exposes it (weak symbol), falling back to the legacy 8-byte salt otherwise. - debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the BUNDLED expat (applied on ubuntu16.04 only; el7 on the RPM side) so the 16-byte salt path above is not inert; other platforms link system expat. - CVE-2026-7210 * SECURITY UPDATE: bz2.BZ2Decompressor reuse after error (stack overflow) - debian/patches/CVE-2026-9669.patch: record the libbz2 error and raise ValueError on any subsequent decompress() call instead of re-entering libbz2 on an inconsistent stream (CWE-121). - CVE-2026-9669
Updated packages:
  • alt-python311_3.11.15-3_amd64.deb
    sha:1efd5c6ce5f2bf069ca738f5fa0419196f8d43af
  • alt-python311-debug_3.11.15-3_amd64.deb
    sha:aa9cae63e1b75ba14db6da64dcbe20179575eb73
  • alt-python311-devel_3.11.15-3_amd64.deb
    sha:7e0881cf5ba4322cc2c454d41dde4d5aaaa946c1
  • alt-python311-idle_3.11.15-3_amd64.deb
    sha:1175d87099dc4c7f956a5f66cbe086194b2af1d5
  • alt-python311-libs_3.11.15-3_amd64.deb
    sha:a7627af85518fac293d2d2f7fe2f9b20e022ba21
  • alt-python311-test_3.11.15-3_amd64.deb
    sha:9f477492cbd8e1500b8a531d778c8c60a673db7d
  • alt-python311-tkinter_3.11.15-3_amd64.deb
    sha:1cedf33cf5664d2de51ba1e7f2a2c8b60292dc83
  • alt-python311_3.11.15-3_arm64.deb
    sha:064b2004e99714ee8979872ddab2d176d00ad1fa
  • alt-python311-debug_3.11.15-3_arm64.deb
    sha:c03f27855d7e312a9edb23f0bfab0479ce11cf04
  • alt-python311-devel_3.11.15-3_arm64.deb
    sha:efcbcf64bc5735c0102d14b8512d2b69ad4e8177
  • alt-python311-idle_3.11.15-3_arm64.deb
    sha:2889c9a1a99a7ff33bb0deda247aad6c0b84ffcf
  • alt-python311-libs_3.11.15-3_arm64.deb
    sha:b112aefb600a39c6e94f43d71f2143e78e72a01c
  • alt-python311-test_3.11.15-3_arm64.deb
    sha:b867a4fdced0d499f624fe8107b259b4bbdb4d2c
  • alt-python311-tkinter_3.11.15-3_arm64.deb
    sha:fc36b362c0cdf09a596173309d406ad3679a3dcf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.