[CLSA-2026:1784300728] alt-python39: Fix of 24 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-17 18:08:42 UTC
Description:
- CVE-2026-9669: bz2.BZ2Decompressor records the libbz2 error code after a decompression failure and refuses any subsequent decompress() call with ValueError, instead of re-entering BZ2_bzDecompress() on an inconsistent bz_stream which could cause a stack buffer overflow (CWE-121).
Updated packages:
  • alt-python39-3.9.23-17.el9.x86_64.rpm
    sha:2adf7efb5713b4f159e34bb18ee2462b865f178b4bd11f401c72ba9436953950
  • alt-python39-debug-3.9.23-17.el9.x86_64.rpm
    sha:27fed7ad19d37099c26b236233d35c31b21d32ef724f50ed8223c15931503bb0
  • alt-python39-devel-3.9.23-17.el9.x86_64.rpm
    sha:a033747a6bb22857c1df6d96099c934c178f3ec50cfd0489d7a241ade20aaf0b
  • alt-python39-idle-3.9.23-17.el9.x86_64.rpm
    sha:4e2288a48be531bce39cafe601d091c59837996bf6636a0e7d088fc48fae495a
  • alt-python39-libs-3.9.23-17.el9.x86_64.rpm
    sha:3fb224c28251ff7c048ef1d6fbe4b7203c659f061615291850cee1ae4eea27c2
  • alt-python39-test-3.9.23-17.el9.x86_64.rpm
    sha:faf4c1c59a9206ec2bcbc0240ce0ff81416d71693f680e7dcc55dec991602501
  • alt-python39-tkinter-3.9.23-17.el9.x86_64.rpm
    sha:ad7a084488416a25d9ae983e73f8b8360bf2af48c525fa8f5eb8472b4d2c6df5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.