[CLSA-2026:1784827891] Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-23 17:32:19 UTC
Description:
* SECURITY UPDATE: webbrowser.open() dash-prefix check bypass via the action token - debian/patches/CVE-2026-4786.patch: validate the action-expanded URL and reorder the action/URL substitution so a URL containing the action token cannot expand into a dash-prefixed browser flag (CVE-2026-4519 bypass). - CVE-2026-4786 * SECURITY UPDATE: dangling input pointer (UAF) in bz2/lzma decompressors - debian/patches/CVE-2026-6100.patch: clear next_in on the MemoryError error path in _bz2/_lzma decompress() so a reused decompressor cannot read or write through a stale pointer to the released input buffer. - CVE-2026-6100 * SECURITY UPDATE: insufficient Expat hash-flooding entropy - debian/patches/CVE-2026-7210.patch: seed Expat with 16 bytes of entropy via XML_SetHashSalt16Bytes when libexpat exposes it (weak symbol), falling back to the legacy 8-byte salt otherwise. - debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the BUNDLED expat (applied on ubuntu16.04 only; el7 on the RPM side) so the 16-byte salt path above is not inert; other platforms link system expat. - CVE-2026-7210 * SECURITY UPDATE: bz2.BZ2Decompressor reuse after error (stack overflow) - debian/patches/CVE-2026-9669.patch: record the libbz2 error and raise ValueError on any subsequent decompress() call instead of re-entering libbz2 on an inconsistent stream (CWE-121). - CVE-2026-9669
Updated packages:
  • alt-python311_3.11.15-3_amd64.deb
    sha:97595c493c32c13a512ecaa6d6a805777263d9b1
  • alt-python311-debug_3.11.15-3_amd64.deb
    sha:aa9cae63e1b75ba14db6da64dcbe20179575eb73
  • alt-python311-devel_3.11.15-3_amd64.deb
    sha:19ff1c0a6a1f84945f418e8fba5e38370fba0ada
  • alt-python311-idle_3.11.15-3_amd64.deb
    sha:89e8152fd9a8a99243ef6987df1cab0771467770
  • alt-python311-libs_3.11.15-3_amd64.deb
    sha:83e49d76a21a47193fd2e7f32fb8ce7b59ff33d2
  • alt-python311-test_3.11.15-3_amd64.deb
    sha:5d1d2b00878a11e8ad51a6692cc9b17f7f4a8dbd
  • alt-python311-tkinter_3.11.15-3_amd64.deb
    sha:7974e5d6ba4d997ddeff90bf76a98313c51a1acf
  • alt-python311_3.11.15-3_arm64.deb
    sha:e552a0d3193c82cfeb7436bd8cde15270a482924
  • alt-python311-debug_3.11.15-3_arm64.deb
    sha:c03f27855d7e312a9edb23f0bfab0479ce11cf04
  • alt-python311-devel_3.11.15-3_arm64.deb
    sha:9959a8bf9dbccad93011493046b7de18bbb5779e
  • alt-python311-idle_3.11.15-3_arm64.deb
    sha:b22f1b1fbfca99a0a372b4d66ac6a098f8bda2e1
  • alt-python311-libs_3.11.15-3_arm64.deb
    sha:c743a8a3c92b4264aa48fb88f7cb9f5be79c1ed4
  • alt-python311-test_3.11.15-3_arm64.deb
    sha:af47e9805e4d2fac8dc990f3ced94fe13c8c29b4
  • alt-python311-tkinter_3.11.15-3_arm64.deb
    sha:afb87a33f98f7c848e12e7fc595adaed73b956f8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.