[CLSA-2026:1784828322] alt-python311: Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-23 17:39:30 UTC
Description:
- CVE-2026-4786: reject action-token-expanded dash-prefixed args in webbrowser.open() (CVE-2026-4519 bypass) - CVE-2026-6100: fix dangling next_in pointer (UAF) in bz2/lzma decompressors after MemoryError on reuse - CVE-2026-7210: use XML_SetHashSalt16Bytes 16-byte entropy for Expat hash-flooding protection when available - CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (ubuntu16.04 / el7; other platforms link system expat) so the CVE-2026-7210 16-byte salt path is not inert - CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression error (stack buffer overflow)
Updated packages:
  • alt-python311-3.11.15-3.el10.x86_64.rpm
    sha:43a421529b535cf6fd8d09a3fba551486fff42c36b6f34419d1065420a0bdd06
  • alt-python311-debug-3.11.15-3.el10.x86_64.rpm
    sha:d1e251853c77c9985677b178f8f433ee750a759bca9e1ef5b4ba61350dc6bd8f
  • alt-python311-devel-3.11.15-3.el10.x86_64.rpm
    sha:097d011f7821a91f3b0486363b1af4492725b1e57422298e69d2654cd011ae41
  • alt-python311-idle-3.11.15-3.el10.x86_64.rpm
    sha:16b6228070932125803e488c612c7c60d66f196dcdc24051c9d2a418824aef4c
  • alt-python311-libs-3.11.15-3.el10.x86_64.rpm
    sha:690eddfe50f08a323351185bacb6dc6cbd1fd3baa87bcfcbdf409117e54cc59e
  • alt-python311-test-3.11.15-3.el10.x86_64.rpm
    sha:035940fc79fb486245b96302b824cdcda8bdd2c9a02fe5175187060ba6969949
  • alt-python311-tkinter-3.11.15-3.el10.x86_64.rpm
    sha:09c577d755265cacde883b81351f2741c5b1dae41fc42385c4f00db6210dc00a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.