[CLSA-2026:1784820336] alt-python311: Fix of 9 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-23 15:26:23 UTC
Description:
- CVE-2026-4786: reject action-token-expanded dash-prefixed args in webbrowser.open() (CVE-2026-4519 bypass) - CVE-2026-6100: fix dangling next_in pointer (UAF) in bz2/lzma decompressors after MemoryError on reuse - CVE-2026-7210: use XML_SetHashSalt16Bytes 16-byte entropy for Expat hash-flooding protection when available - CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (ubuntu16.04 / el7; other platforms link system expat) so the CVE-2026-7210 16-byte salt path is not inert - CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression error (stack buffer overflow)
Updated packages:
  • alt-python311-3.11.15-3.el8.x86_64.rpm
    sha:f75a8078064aeb30d1161f3a2da53ca1508aa844b9855b03b6783cfea8c16fec
  • alt-python311-debug-3.11.15-3.el8.x86_64.rpm
    sha:2bc48753bced2cb87363634dce736275844de5664ef42925a701d8543047bc50
  • alt-python311-devel-3.11.15-3.el8.x86_64.rpm
    sha:e0d0044ccac29ea1e46aeb05ef4de9968f90a10a04afbff63d725c2f37c0ec0f
  • alt-python311-idle-3.11.15-3.el8.x86_64.rpm
    sha:72c239300bafc40da96b1437ba36bebbf6fbaead4875af5195dd0753c5fa4e3f
  • alt-python311-libs-3.11.15-3.el8.x86_64.rpm
    sha:74548432fadc972166e3c36f845d80630f84c5635be52487d7225e78d92286a5
  • alt-python311-test-3.11.15-3.el8.x86_64.rpm
    sha:162e1ad23b8619244df5ff0d6f1755ba951664795c5ceee126df5c66e910ef47
  • alt-python311-tkinter-3.11.15-3.el8.x86_64.rpm
    sha:75562325b7b78b4d15f9b843b9680ac76043f9f56e9e309d8b92ca13e164b6f3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.