[CLSA-2026:1790163766] alt-python310: Fix of CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 11:42:59 UTC
Description:
- ALTPYTH-616: Update to 3.10.21 - Drop 06003-ssl-use-bio_eof-for-asn1-cadata-eof.patch, included in upstream 3.10.21 - Drop CVE backports included in upstream 3.10.21: CVE-2026-3644, CVE-2026-4224, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-9669, CVE-2026-41080, CVE-2026-15308, CVE-2025-13462, CVE-2026-8328, CVE-2026-7774, CVE-2026-1502, CVE-2026-3276, CVE-2026-0864, CVE-2026-11972, CVE-2026-11940, CVE-2026-6879 - Require expat >= 2.4.0 on rhel > 7: 3.10.21 calls XML_SetBillionLaughsAttackProtectionActivationThreshold and ...MaximumAmplification, which are required (non-weak) symbols in pyexpat. libexpat has no symbol versioning, so RPM records only libexpat.so.1()(64bit) and cannot derive the floor; on an older expat the package installs and then fails at import with "undefined symbol". CL7 keeps the bundled expat - Re-anchor the Include/pyexpat.h hunk of CVE-2026-7210.patch onto the 3.10.21 PyExpat_CAPI layout (3.10.21 inserted the SetBillionLaughsAttackProtection* members before the end-of-struct sentinel) so it applies with --fuzz=0
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-1.el8.x86_64.rpm
    sha:a2d3bf8a77ca5f3ecc167afd8014fa2072fa8976eee96277653221f991262d0b
  • alt-python310-debug-3.10.21-1.el8.x86_64.rpm
    sha:80f7c670ae29d5754726ccd91eb67a32c4619312886699b8bf567999265fef24
  • alt-python310-devel-3.10.21-1.el8.x86_64.rpm
    sha:dbf7b7fbb1eee5d4b0752147764b0c9e34b7731074d2a42885ebf38375e0d64b
  • alt-python310-idle-3.10.21-1.el8.x86_64.rpm
    sha:a78a268ca7be3dc80a9b8a04c2c24724d265e917ffb0f089956f9d5aa70158b6
  • alt-python310-libs-3.10.21-1.el8.x86_64.rpm
    sha:3f0b8d5d6f2b80008c3f08ea1e8c526dc189bf9dffc5c5c6a719a94f62d41bdd
  • alt-python310-test-3.10.21-1.el8.x86_64.rpm
    sha:b138fade0ba87e234e821341a3c4ccc2b8ef04423a9a6635e7dff5b3c9832b77
  • alt-python310-tkinter-3.10.21-1.el8.x86_64.rpm
    sha:bf3b39d2e5e3ebf42dee976ae4089fa630589826cddb0261a01e4b0c2da4ca8b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.