[CLSA-2026:1784880757] alt-python310: Fix of 12 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-24 08:13:31 UTC
Description:
- CVE-2026-4786: fix action-substitution bypass of the CVE-2026-4519 webbrowser dash-prefix check - CVE-2026-6100: clear decompressor next_in on the error path in bz2/lzma to prevent use-after-free - CVE-2026-7210: use XML_SetHashSalt16Bytes for 16-byte Expat hash-flooding entropy - CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (Debian/Ubuntu, el7) so the CVE-2026-7210 16-byte salt path is not inert - CVE-2026-9669: refuse bz2 decompressor reuse after a previous error to prevent stack buffer overflow
Updated packages:
  • alt-python310-3.10.20-3.el10.x86_64.rpm
    sha:8f7e4cb941007f2afc98a44bfd8e9b2ba5a4bbb8a38e1b9741e121abcafa1e69
  • alt-python310-debug-3.10.20-3.el10.x86_64.rpm
    sha:6575caf1cce5052fb9ba4a96778659f7cdeef552085317811c79c5b0c217f9e8
  • alt-python310-devel-3.10.20-3.el10.x86_64.rpm
    sha:b6d1091058a4573c68b8ac11475e8891334aeb5d4311c085b93b9feae925bd1d
  • alt-python310-idle-3.10.20-3.el10.x86_64.rpm
    sha:eb19d6d9aada9ae3ee701c035458eb752f6337633a9e4d4af911b7df5d6cb79b
  • alt-python310-libs-3.10.20-3.el10.x86_64.rpm
    sha:0635f9867717010394416641d3873eb631dcdf513fb71b9ce4aa3a4a724f3509
  • alt-python310-test-3.10.20-3.el10.x86_64.rpm
    sha:c83a83da87372338f70ae9180dfe28c1a592f1c9474a86c75c31ec72d52a2995
  • alt-python310-tkinter-3.10.20-3.el10.x86_64.rpm
    sha:4788fdfab1ff0a21c95a21e649aa7c6577fa673554db3c879d7bb611c5ed6c32
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.