[CLSA-2026:1785429751] alt-python310: Fix of 12 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 18:46:51 UTC
Description:
- CVE-2026-3446: stop ignoring excess base64 data after the first padded quad in binascii.a2b_base64(), which backs base64.b64decode() - CVE-2026-11940: revalidate the hardlink's own shallower path in the tarfile extraction fallback so a symlink cannot escape the destination directory, and pass the extraction filter from extract() down to _extract_one() so the revalidation runs for single-member extraction as well and not only for extractall() - CVE-2026-6019: percent-encode the cookie value embedded in the http.cookies Morsel.js_output() script snippet and decode it with decodeURIComponent() to prevent breaking out of the script element while keeping UTF-8 values intact
Updated packages:
  • alt-python310-3.10.20-9.el10.x86_64.rpm
    sha:bae8f8bb13248b31090db658ca08379424ba91c1d638395f5ef59d9d7f19fceb
  • alt-python310-debug-3.10.20-9.el10.x86_64.rpm
    sha:e6e1be597500045ad99940793a04ac429379c2291fd1ef78776f8cc997a78e7d
  • alt-python310-devel-3.10.20-9.el10.x86_64.rpm
    sha:d67457be0389f3d98ff97d88906448b628df2b5794604e7242fb2b85202f8520
  • alt-python310-idle-3.10.20-9.el10.x86_64.rpm
    sha:1b8fef3d557f7da861a584afa50dc43c069e15f8a75fc766410bc1f89f64c25a
  • alt-python310-libs-3.10.20-9.el10.x86_64.rpm
    sha:d41ad762febb33735b67e940ead79912c7b949e268132ffaea552ff0b6b4707f
  • alt-python310-test-3.10.20-9.el10.x86_64.rpm
    sha:6bcecb68733c1c6dbb70b612a6d6b431097fed5c560359a24d178c1a4eefbfe1
  • alt-python310-tkinter-3.10.20-9.el10.x86_64.rpm
    sha:f84dda0472d4ec596ff7647d0f8f8ca4c33164060b48c8537d8cde59ab556bed
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.