[CLSA-2026:1784882507] alt-python310: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-24 08:42:20 UTC
Description:
- CVE-2026-4786: fix action-substitution bypass of the CVE-2026-4519 webbrowser dash-prefix check - CVE-2026-6100: clear decompressor next_in on the error path in bz2/lzma to prevent use-after-free - CVE-2026-7210: use XML_SetHashSalt16Bytes for 16-byte Expat hash-flooding entropy - CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (Debian/Ubuntu, el7) so the CVE-2026-7210 16-byte salt path is not inert - CVE-2026-9669: refuse bz2 decompressor reuse after a previous error to prevent stack buffer overflow
Updated packages:
  • alt-python310-3.10.20-3.el8.x86_64.rpm
    sha:9997e112f089ca108a09b35e5c42f09f34632a2aee87eef08e2b85b50b6a819b
  • alt-python310-debug-3.10.20-3.el8.x86_64.rpm
    sha:217875973717d35ac979cddd0bc8634a0566b4928bfadd955df40ba344f9cdb9
  • alt-python310-devel-3.10.20-3.el8.x86_64.rpm
    sha:2bd84f67a5c97e6fe71f81cbe842110a83480d3d19cd7e9f72df6fc379259462
  • alt-python310-idle-3.10.20-3.el8.x86_64.rpm
    sha:e9f195c8893037babe57d62abe1f7546d4861c609d67b54a6e2ed264c743f527
  • alt-python310-libs-3.10.20-3.el8.x86_64.rpm
    sha:ff5777e9ca448a9c1b387de4cabb3d8fa1d41acb8d592ad3a141f866097b5c51
  • alt-python310-test-3.10.20-3.el8.x86_64.rpm
    sha:e919c05b0e9327ff512887cbaa64f8cde78177ef0727ef9c5122d3ea170cfc53
  • alt-python310-tkinter-3.10.20-3.el8.x86_64.rpm
    sha:1838691a5ee3bb2696a832a274cd4dd58081a0d64f9e24356dd73eae9236c3da
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.