[CLSA-2026:1785421476] alt-python39: Fix of CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:24:47 UTC
Description:
- CVE-2025-12781: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). Backport of cpython 9060b4ab (gh-125346, PR gh-141128): emits DeprecationWarning/FutureWarning when such characters are seen; decoded output is unchanged.
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-21.el7.x86_64.rpm
    sha:335d22daad426df0054eaecd2fefe95c924c2d011c5467dd54d65cc5c993a4be
  • alt-python39-debug-3.9.23-21.el7.x86_64.rpm
    sha:8018b1869a75aef3af8ee90c758e5bcbb0b771db9605d05e4eec272d84575bed
  • alt-python39-devel-3.9.23-21.el7.x86_64.rpm
    sha:65029fe054945bfe8179bd269e77bdc0a575b541e3d841220e8ff316c505fc06
  • alt-python39-idle-3.9.23-21.el7.x86_64.rpm
    sha:f8701ee2a56b80abad3bab34ea56a14b76d089c65bb3d888d0ca69af3da71897
  • alt-python39-libs-3.9.23-21.el7.x86_64.rpm
    sha:ba87e5987c8c919ff1df6cd9e56d09c2a9512c2d0bd65cb2c0853aaf26973d65
  • alt-python39-test-3.9.23-21.el7.x86_64.rpm
    sha:922642fa6dc92e4afe4798d11d0bc65268eb16a62b84096f8d40d4bd4ba88109
  • alt-python39-tkinter-3.9.23-21.el7.x86_64.rpm
    sha:42c9720e92805b829ddf75efe8cad5f96a78bd793a1ef7648047b7ce6d254fe2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.