[CLSA-2026:1784814992] Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-23 13:57:20 UTC
Description:
* SECURITY UPDATE: webbrowser argument injection via action-token substitution - debian/patches/CVE-2026-4786.patch: validate expanded command (bypass of CVE-2026-4519) - CVE-2026-4786 * SECURITY UPDATE: use-after-free in bz2/lzma decompressor reuse after MemoryError - debian/patches/CVE-2026-6100.patch: clear next_in on the decompress error path - CVE-2026-6100 * SECURITY UPDATE: insufficient entropy for Expat hash-flooding protection - debian/patches/CVE-2026-7210.patch: use XML_SetHashSalt16Bytes 16-byte entropy - CVE-2026-7210 * SECURITY UPDATE: insufficient entropy in bundled Expat (libexpat) hash-flooding protection - debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the bundled expat so the CVE-2026-7210 16-byte salt path is not inert on bundled-expat builds - CVE-2026-41080 * SECURITY UPDATE: stack buffer overflow via bz2 decompressor reuse after error - debian/patches/CVE-2026-9669.patch: refuse reuse after a previous error - CVE-2026-9669
Updated packages:
  • alt-python310_3.10.20-4_amd64.deb
    sha:8f876080a2d9b9a2f6f4dd861456bfd2a3a3e650
  • alt-python310-debug_3.10.20-4_amd64.deb
    sha:39afe7916ea28193cd4b3fbbec31b255d752b836
  • alt-python310-devel_3.10.20-4_amd64.deb
    sha:61f4653a3bc630860550c09f82b4fd2400f81083
  • alt-python310-idle_3.10.20-4_amd64.deb
    sha:50ead04178a85bf2c52178ea7c370e0bd0f5457f
  • alt-python310-libs_3.10.20-4_amd64.deb
    sha:84c36bc3b00362dae202730ae4776743cb7d87db
  • alt-python310-test_3.10.20-4_amd64.deb
    sha:0b57ac9189ca2bdc08a4576fdb33655a3995db41
  • alt-python310-tkinter_3.10.20-4_amd64.deb
    sha:1857d4bb6350eb93f145ba6210f874105ba4f8f8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.