[CLSA-2026:1790159078] alt-python310: Fix of CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 10:24:49 UTC
Description:
- ALTPYTH-616: Update to 3.10.21 - Drop 06003-ssl-use-bio_eof-for-asn1-cadata-eof.patch, included in upstream 3.10.21 - Drop CVE backports included in upstream 3.10.21: CVE-2026-3644, CVE-2026-4224, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-9669, CVE-2026-41080, CVE-2026-15308, CVE-2025-13462, CVE-2026-8328, CVE-2026-7774, CVE-2026-1502, CVE-2026-3276, CVE-2026-0864, CVE-2026-11972, CVE-2026-11940, CVE-2026-6879 - Require expat >= 2.4.0 on rhel > 7: 3.10.21 calls XML_SetBillionLaughsAttackProtectionActivationThreshold and ...MaximumAmplification, which are required (non-weak) symbols in pyexpat. libexpat has no symbol versioning, so RPM records only libexpat.so.1()(64bit) and cannot derive the floor; on an older expat the package installs and then fails at import with "undefined symbol". CL7 keeps the bundled expat - Re-anchor the Include/pyexpat.h hunk of CVE-2026-7210.patch onto the 3.10.21 PyExpat_CAPI layout (3.10.21 inserted the SetBillionLaughsAttackProtection* members before the end-of-struct sentinel) so it applies with --fuzz=0
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-1.el7.x86_64.rpm
    sha:fb08812a0addbb52e61ae074617327dcae4e31ef8ffe52ffb62130a1f0c89893
  • alt-python310-debug-3.10.21-1.el7.x86_64.rpm
    sha:ec921df4016666440a32c6302483ef159f71c9e46948973eacd888bd5452d735
  • alt-python310-devel-3.10.21-1.el7.x86_64.rpm
    sha:e160aa4c6d87ce8a8d01d351177b45a0e3aa54ed7aabcb01f3d3c5b80b8663ea
  • alt-python310-idle-3.10.21-1.el7.x86_64.rpm
    sha:26ce3c36f3dd9d0062b8374c0cd74a155c5b3c8dcaa00b3bc35edbd226e06f3c
  • alt-python310-libs-3.10.21-1.el7.x86_64.rpm
    sha:a867499a2b996f455d33cbc95a7e82e7e95e4c131418638dcda5e9673c6ceb94
  • alt-python310-test-3.10.21-1.el7.x86_64.rpm
    sha:c0839d79ac09da0d47e3d63d0622f97ed4921e99b06b5b1462ccac3ec1372208
  • alt-python310-tkinter-3.10.21-1.el7.x86_64.rpm
    sha:33e5c5276fbe06ddacb8be305f2a19d12c5acb47105a807fd6d61d67269b5fa9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.