[CLSA-2026:1784825498] Fix CVE(s): CVE-2026-4786, CVE-2026-6100, CVE-2026-7210, CVE-2026-9669
Type:
security
Severity:
Critical
Release date:
2026-07-23 16:52:11 UTC
Description:
* SECURITY UPDATE: webbrowser argument injection via action-token substitution - debian/patches/CVE-2026-4786.patch: validate expanded command (bypass of CVE-2026-4519) - CVE-2026-4786 * SECURITY UPDATE: use-after-free in bz2/lzma decompressor reuse after MemoryError - debian/patches/CVE-2026-6100.patch: clear next_in on the decompress error path - CVE-2026-6100 * SECURITY UPDATE: insufficient entropy for Expat hash-flooding protection - debian/patches/CVE-2026-7210.patch: use XML_SetHashSalt16Bytes 16-byte entropy - CVE-2026-7210 * SECURITY UPDATE: insufficient entropy in bundled Expat (libexpat) hash-flooding protection - debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the bundled expat so the CVE-2026-7210 16-byte salt path is not inert on bundled-expat builds - CVE-2026-41080 * SECURITY UPDATE: stack buffer overflow via bz2 decompressor reuse after error - debian/patches/CVE-2026-9669.patch: refuse reuse after a previous error - CVE-2026-9669
Updated packages:
  • alt-python310_3.10.20-4_amd64.deb
    sha:8d61bd461d2301cc5c5229b051de8b187fc37fe7
  • alt-python310-debug_3.10.20-4_amd64.deb
    sha:4c3aaf0428044f67d05e7aa8b289b4df2cc2fbd8
  • alt-python310-devel_3.10.20-4_amd64.deb
    sha:885b1bdca7ef1e13c6174bf912bbaff8591405f4
  • alt-python310-idle_3.10.20-4_amd64.deb
    sha:92a180462f7c58bcccda78007ae875b5ea54b0fb
  • alt-python310-libs_3.10.20-4_amd64.deb
    sha:b53c4eacf60a889867aeaf32516de9285a89e359
  • alt-python310-test_3.10.20-4_amd64.deb
    sha:5b7e465b8dd6ac2dc9c75f273668470753d8dc86
  • alt-python310-tkinter_3.10.20-4_amd64.deb
    sha:f423ecaafd2a076b6a950b87b6711d8bc0f27e9d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.