[CLSA-2026:1784805312] alt-python39: Fix of CVE-2026-15308
Type:
security
Severity:
Important
Release date:
2026-07-23 11:15:37 UTC
Description:
- el10: build _decimal against system libmpdec (BuildRequires mpdecimal-devel, configure --with-system-libmpdec, patch setup.py to link -lmpdec since el10 ships libmpdec.so.3 not .so.2, and _decimal.c uchar->unsigned char for the mpdecimal 2.5 api); the bundled libmpdec fails to compile with -Og under the el10 gcc, which broke the CL10 build - el10: apply 06003 (BIO_eof ASN1 EOF, CPython gh-100372) so test_ssl cadata tests pass with OpenSSL 3.5.x, matching the alpine build (ALTPYTH-611)
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-19.el8.x86_64.rpm
    sha:abdb3b01ab166d52ecd1eb83eb26fb76441c9eade270c1d6342366e158989a8f
  • alt-python39-debug-3.9.23-19.el8.x86_64.rpm
    sha:e9d02c205aa40c50b6c2e68f19208d7c55273707b998d36ee57767d4b654b2e8
  • alt-python39-devel-3.9.23-19.el8.x86_64.rpm
    sha:c3fae74694223c1886b7f4442c6f3a828d84af7220f6cc1b13e638a5e9f8c625
  • alt-python39-idle-3.9.23-19.el8.x86_64.rpm
    sha:caec99686413d7f6ff84a866dda243dec4b4770dac9616026fa77f1d8c97997e
  • alt-python39-libs-3.9.23-19.el8.x86_64.rpm
    sha:596af1406b2c8e6db3541d660cfe0ae0be2eecfdcf3d53a223c10e3caf3cc6df
  • alt-python39-test-3.9.23-19.el8.x86_64.rpm
    sha:baffd60f3ef077ce435288cc0b136fc00110482f90d5a06af47131cc796489fd
  • alt-python39-tkinter-3.9.23-19.el8.x86_64.rpm
    sha:1a5aa69d24b5d234244e6813efd3a8eab477bc796a1efdce020dbc0f48cd659f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.