Release date:
2026-07-24 08:42:20 UTC
Description:
- CVE-2026-4786: fix action-substitution bypass of the CVE-2026-4519 webbrowser dash-prefix check
- CVE-2026-6100: clear decompressor next_in on the error path in bz2/lzma to prevent use-after-free
- CVE-2026-7210: use XML_SetHashSalt16Bytes for 16-byte Expat hash-flooding entropy
- CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (Debian/Ubuntu, el7) so the CVE-2026-7210 16-byte salt path is not inert
- CVE-2026-9669: refuse bz2 decompressor reuse after a previous error to prevent stack buffer overflow
Updated packages:
-
alt-python310-3.10.20-3.el8.x86_64.rpm
sha:9997e112f089ca108a09b35e5c42f09f34632a2aee87eef08e2b85b50b6a819b
-
alt-python310-debug-3.10.20-3.el8.x86_64.rpm
sha:217875973717d35ac979cddd0bc8634a0566b4928bfadd955df40ba344f9cdb9
-
alt-python310-devel-3.10.20-3.el8.x86_64.rpm
sha:2bd84f67a5c97e6fe71f81cbe842110a83480d3d19cd7e9f72df6fc379259462
-
alt-python310-idle-3.10.20-3.el8.x86_64.rpm
sha:e9f195c8893037babe57d62abe1f7546d4861c609d67b54a6e2ed264c743f527
-
alt-python310-libs-3.10.20-3.el8.x86_64.rpm
sha:ff5777e9ca448a9c1b387de4cabb3d8fa1d41acb8d592ad3a141f866097b5c51
-
alt-python310-test-3.10.20-3.el8.x86_64.rpm
sha:e919c05b0e9327ff512887cbaa64f8cde78177ef0727ef9c5122d3ea170cfc53
-
alt-python310-tkinter-3.10.20-3.el8.x86_64.rpm
sha:1838691a5ee3bb2696a832a274cd4dd58081a0d64f9e24356dd73eae9236c3da
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.