Release date:
2026-07-23 17:39:30 UTC
Description:
- CVE-2026-4786: reject action-token-expanded dash-prefixed args in webbrowser.open() (CVE-2026-4519 bypass)
- CVE-2026-6100: fix dangling next_in pointer (UAF) in bz2/lzma decompressors after MemoryError on reuse
- CVE-2026-7210: use XML_SetHashSalt16Bytes 16-byte entropy for Expat hash-flooding protection when available
- CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (ubuntu16.04 / el7; other platforms link system expat) so the CVE-2026-7210 16-byte salt path is not inert
- CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression error (stack buffer overflow)
Updated packages:
-
alt-python311-3.11.15-3.el10.x86_64.rpm
sha:43a421529b535cf6fd8d09a3fba551486fff42c36b6f34419d1065420a0bdd06
-
alt-python311-debug-3.11.15-3.el10.x86_64.rpm
sha:d1e251853c77c9985677b178f8f433ee750a759bca9e1ef5b4ba61350dc6bd8f
-
alt-python311-devel-3.11.15-3.el10.x86_64.rpm
sha:097d011f7821a91f3b0486363b1af4492725b1e57422298e69d2654cd011ae41
-
alt-python311-idle-3.11.15-3.el10.x86_64.rpm
sha:16b6228070932125803e488c612c7c60d66f196dcdc24051c9d2a418824aef4c
-
alt-python311-libs-3.11.15-3.el10.x86_64.rpm
sha:690eddfe50f08a323351185bacb6dc6cbd1fd3baa87bcfcbdf409117e54cc59e
-
alt-python311-test-3.11.15-3.el10.x86_64.rpm
sha:035940fc79fb486245b96302b824cdcda8bdd2c9a02fe5175187060ba6969949
-
alt-python311-tkinter-3.11.15-3.el10.x86_64.rpm
sha:09c577d755265cacde883b81351f2741c5b1dae41fc42385c4f00db6210dc00a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.