[CLSA-2026:1785422123] alt-python39: Fix of CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:35:35 UTC
Description:
- CVE-2025-12781: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). Backport of cpython 9060b4ab (gh-125346, PR gh-141128): emits DeprecationWarning/FutureWarning when such characters are seen; decoded output is unchanged.
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-21.el9.x86_64.rpm
    sha:2434702663f7b84fcf8d2f3aeaa2436f772945091ec08cd9aa9ac68a13fa2668
  • alt-python39-debug-3.9.23-21.el9.x86_64.rpm
    sha:08779020ead59ac475b4da1278a701b6c86dd4077961bf09b3bbde5ad39cb5a9
  • alt-python39-devel-3.9.23-21.el9.x86_64.rpm
    sha:9d4ad9201d2ff4bf8b9031f9bfe77504a9db5d9a8c8ee2cdd901b70b41e500df
  • alt-python39-idle-3.9.23-21.el9.x86_64.rpm
    sha:cf26200c4551dab12825bc37f932863da56c443ccb1d7fe4b2df93f8697e8cad
  • alt-python39-libs-3.9.23-21.el9.x86_64.rpm
    sha:f2fa50bd142892bed92b4039d76567a378de2ed7857561606f72cf3b6c89caf3
  • alt-python39-test-3.9.23-21.el9.x86_64.rpm
    sha:02458f330fbf8e5e813f3d56650f48b14233a6cfe5714f9f91d8b456704fe379
  • alt-python39-tkinter-3.9.23-21.el9.x86_64.rpm
    sha:864990e5cf4e99e50758198100546c6b278265b9af98d70b249691963e8eb3e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.