Release date:
2026-07-23 13:57:20 UTC
Description:
* SECURITY UPDATE: webbrowser argument injection via action-token substitution
- debian/patches/CVE-2026-4786.patch: validate expanded command (bypass of CVE-2026-4519)
- CVE-2026-4786
* SECURITY UPDATE: use-after-free in bz2/lzma decompressor reuse after MemoryError
- debian/patches/CVE-2026-6100.patch: clear next_in on the decompress error path
- CVE-2026-6100
* SECURITY UPDATE: insufficient entropy for Expat hash-flooding protection
- debian/patches/CVE-2026-7210.patch: use XML_SetHashSalt16Bytes 16-byte entropy
- CVE-2026-7210
* SECURITY UPDATE: insufficient entropy in bundled Expat (libexpat) hash-flooding protection
- debian/patches/CVE-2026-41080.patch: backport XML_SetHashSalt16Bytes into the bundled expat so the CVE-2026-7210 16-byte salt path is not inert on bundled-expat builds
- CVE-2026-41080
* SECURITY UPDATE: stack buffer overflow via bz2 decompressor reuse after error
- debian/patches/CVE-2026-9669.patch: refuse reuse after a previous error
- CVE-2026-9669
Updated packages:
-
alt-python310_3.10.20-4_amd64.deb
sha:8f876080a2d9b9a2f6f4dd861456bfd2a3a3e650
-
alt-python310-debug_3.10.20-4_amd64.deb
sha:39afe7916ea28193cd4b3fbbec31b255d752b836
-
alt-python310-devel_3.10.20-4_amd64.deb
sha:61f4653a3bc630860550c09f82b4fd2400f81083
-
alt-python310-idle_3.10.20-4_amd64.deb
sha:50ead04178a85bf2c52178ea7c370e0bd0f5457f
-
alt-python310-libs_3.10.20-4_amd64.deb
sha:84c36bc3b00362dae202730ae4776743cb7d87db
-
alt-python310-test_3.10.20-4_amd64.deb
sha:0b57ac9189ca2bdc08a4576fdb33655a3995db41
-
alt-python310-tkinter_3.10.20-4_amd64.deb
sha:1857d4bb6350eb93f145ba6210f874105ba4f8f8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.