[CLSA-2026:1784291554] alt-python39: Fix of 24 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-17 18:03:02 UTC
Description:
- CVE-2026-9669: bz2.BZ2Decompressor records the libbz2 error code after a decompression failure and refuses any subsequent decompress() call with ValueError, instead of re-entering BZ2_bzDecompress() on an inconsistent bz_stream which could cause a stack buffer overflow (CWE-121).
Updated packages:
  • alt-python39-3.9.23-17.el7.x86_64.rpm
    sha:50e69079bdd382447e156872845186445100007662f1638d56c159c919710aa4
  • alt-python39-debug-3.9.23-17.el7.x86_64.rpm
    sha:308dc01acde1df1528f370188006153f494f044c43b6c077cf109aa35accdb03
  • alt-python39-devel-3.9.23-17.el7.x86_64.rpm
    sha:edda0394febc7a4c35968634c1642d058c93e18b9417e8df00a75e678ef3cc47
  • alt-python39-idle-3.9.23-17.el7.x86_64.rpm
    sha:2e96987825be666fe387c685a1e4f471b824292a0c61aa983f6eb7894f5ae21f
  • alt-python39-libs-3.9.23-17.el7.x86_64.rpm
    sha:2cd05743b2a9e1bf5fd23d8d817598435c0c9b586d7101b43cbc14117a54036a
  • alt-python39-test-3.9.23-17.el7.x86_64.rpm
    sha:6980f4c9425da87406c8940f16ac66483b01418a4ce5178bcd026adbeb358bee
  • alt-python39-tkinter-3.9.23-17.el7.x86_64.rpm
    sha:c88dba6809a682c14b8e43f61a4076ca006c19733c8cadc0099dcab7b8ee7562
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.