[CLSA-2026:1784881258] alt-python310: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-24 08:26:38 UTC
Description:
- CVE-2026-4786: fix action-substitution bypass of the CVE-2026-4519 webbrowser dash-prefix check - CVE-2026-6100: clear decompressor next_in on the error path in bz2/lzma to prevent use-after-free - CVE-2026-7210: use XML_SetHashSalt16Bytes for 16-byte Expat hash-flooding entropy - CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (Debian/Ubuntu, el7) so the CVE-2026-7210 16-byte salt path is not inert - CVE-2026-9669: refuse bz2 decompressor reuse after a previous error to prevent stack buffer overflow
Updated packages:
  • alt-python310-3.10.20-3.el7.x86_64.rpm
    sha:4251609021a847d590e8647db9d4f81607d75cda681e447932f55ab7844b74a4
  • alt-python310-debug-3.10.20-3.el7.x86_64.rpm
    sha:4d3b027ee33b88aee1aa46ddbe072aa0e341c3b741409e1d0b63136f558bb2c9
  • alt-python310-devel-3.10.20-3.el7.x86_64.rpm
    sha:80fae811d11b41002e21420ca19ecaa816228fac00187897bf5d627b4b5fc4d6
  • alt-python310-idle-3.10.20-3.el7.x86_64.rpm
    sha:22e3a78dd6c2b9a4d6b10b984980f9c25f0b44f7dbda3aca3519197f68bfc50b
  • alt-python310-libs-3.10.20-3.el7.x86_64.rpm
    sha:3a4cb8c9ac15812489254d7e6feb3a332529aa779ad6f773564b999989e61f76
  • alt-python310-test-3.10.20-3.el7.x86_64.rpm
    sha:7a59cd867efae54f2b681b78d52dcb0d3333704bfa69356675aeb87b7ed2d8f3
  • alt-python310-tkinter-3.10.20-3.el7.x86_64.rpm
    sha:5516333b24d73d0a0f3b228601677ba748376ca186d364f83bd070bebdd2930b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.