Release date:
2026-07-23 19:13:00 UTC
Description:
- CVE-2026-4786: reject action-token-expanded dash-prefixed args in webbrowser.open() (CVE-2026-4519 bypass)
- CVE-2026-6100: fix dangling next_in pointer (UAF) in bz2/lzma decompressors after MemoryError on reuse
- CVE-2026-7210: use XML_SetHashSalt16Bytes 16-byte entropy for Expat hash-flooding protection when available
- CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (ubuntu16.04 / el7; other platforms link system expat) so the CVE-2026-7210 16-byte salt path is not inert
- CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression error (stack buffer overflow)
Updated packages:
-
alt-python311-3.11.15-3.el7.x86_64.rpm
sha:9f8f7feacbe6bb743e55fb00ef640d35e2ebf3dca004eb6499a20bd3097818ad
-
alt-python311-debug-3.11.15-3.el7.x86_64.rpm
sha:495c361844fd326fc0ec523e05a2c5a33d25e4a562899f38b15b5a5f53a72819
-
alt-python311-devel-3.11.15-3.el7.x86_64.rpm
sha:69e969e62d6dbd3c2e14a29fff0dd1f358109ec5507e43028ddc890204570883
-
alt-python311-idle-3.11.15-3.el7.x86_64.rpm
sha:9e381217cfd628a81bdb35452d24c22f579d05d35c3bd980886d7357cca5162c
-
alt-python311-libs-3.11.15-3.el7.x86_64.rpm
sha:9d53962da8467d505e3465ea5947e6a31532263374ef9a5b5111f27aea7b8333
-
alt-python311-test-3.11.15-3.el7.x86_64.rpm
sha:8d2008d0869cb3e97c90127f1ae281f1592bd37dfa1b738b8cd42acf7ca3aca9
-
alt-python311-tkinter-3.11.15-3.el7.x86_64.rpm
sha:eadcf751db74809c2bb40abb9a94c2fa2dbbb8fe77ad3b7c9327ba068060e410
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.