[CLSA-2026:1784882920] alt-python310: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-24 08:49:13 UTC
Description:
- CVE-2026-4786: fix action-substitution bypass of the CVE-2026-4519 webbrowser dash-prefix check - CVE-2026-6100: clear decompressor next_in on the error path in bz2/lzma to prevent use-after-free - CVE-2026-7210: use XML_SetHashSalt16Bytes for 16-byte Expat hash-flooding entropy - CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (Debian/Ubuntu, el7) so the CVE-2026-7210 16-byte salt path is not inert - CVE-2026-9669: refuse bz2 decompressor reuse after a previous error to prevent stack buffer overflow
Updated packages:
  • alt-python310-3.10.20-3.el9.x86_64.rpm
    sha:8186c3d3a84aa6510e51f86330477bb2cdf2eb3445200ec0637e8ca3f88d1499
  • alt-python310-debug-3.10.20-3.el9.x86_64.rpm
    sha:654b3ec14585c020229fa83fb5aee39291fade3ccbcebb5d8f00af031f585b96
  • alt-python310-devel-3.10.20-3.el9.x86_64.rpm
    sha:0f6519efd66a357b878bb6c28b1e62961bcff7affaf94ddf20572a620ba83f8e
  • alt-python310-idle-3.10.20-3.el9.x86_64.rpm
    sha:89cfbd94ef3c646a65bb13473fb26e43a613d0b5e1803b1a8f9c8080841d9030
  • alt-python310-libs-3.10.20-3.el9.x86_64.rpm
    sha:4c5a00dbe166793fc4c5a883be8ee9950d2a32ca3ddfa6bbde5daa4ceb85f47c
  • alt-python310-test-3.10.20-3.el9.x86_64.rpm
    sha:0b0073eecb006d5a170522cef84725ea878f0faa8a8bf3261bd9dcdcbee4cc6d
  • alt-python310-tkinter-3.10.20-3.el9.x86_64.rpm
    sha:631729b219fd2d0563a67bd3c698e29136b4f4af91d04bc67a69ac76188f25fe
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.