[CLSA-2026:1784818766] alt-python311: Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-23 19:13:00 UTC
Description:
- CVE-2026-4786: reject action-token-expanded dash-prefixed args in webbrowser.open() (CVE-2026-4519 bypass) - CVE-2026-6100: fix dangling next_in pointer (UAF) in bz2/lzma decompressors after MemoryError on reuse - CVE-2026-7210: use XML_SetHashSalt16Bytes 16-byte entropy for Expat hash-flooding protection when available - CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (ubuntu16.04 / el7; other platforms link system expat) so the CVE-2026-7210 16-byte salt path is not inert - CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression error (stack buffer overflow)
Updated packages:
  • alt-python311-3.11.15-3.el7.x86_64.rpm
    sha:9f8f7feacbe6bb743e55fb00ef640d35e2ebf3dca004eb6499a20bd3097818ad
  • alt-python311-debug-3.11.15-3.el7.x86_64.rpm
    sha:495c361844fd326fc0ec523e05a2c5a33d25e4a562899f38b15b5a5f53a72819
  • alt-python311-devel-3.11.15-3.el7.x86_64.rpm
    sha:69e969e62d6dbd3c2e14a29fff0dd1f358109ec5507e43028ddc890204570883
  • alt-python311-idle-3.11.15-3.el7.x86_64.rpm
    sha:9e381217cfd628a81bdb35452d24c22f579d05d35c3bd980886d7357cca5162c
  • alt-python311-libs-3.11.15-3.el7.x86_64.rpm
    sha:9d53962da8467d505e3465ea5947e6a31532263374ef9a5b5111f27aea7b8333
  • alt-python311-test-3.11.15-3.el7.x86_64.rpm
    sha:8d2008d0869cb3e97c90127f1ae281f1592bd37dfa1b738b8cd42acf7ca3aca9
  • alt-python311-tkinter-3.11.15-3.el7.x86_64.rpm
    sha:eadcf751db74809c2bb40abb9a94c2fa2dbbb8fe77ad3b7c9327ba068060e410
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.