[CLSA-2026:1785429417] alt-python310: Fix of 12 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 18:42:09 UTC
Description:
- CVE-2026-3446: stop ignoring excess base64 data after the first padded quad in binascii.a2b_base64(), which backs base64.b64decode() - CVE-2026-11940: revalidate the hardlink's own shallower path in the tarfile extraction fallback so a symlink cannot escape the destination directory, and pass the extraction filter from extract() down to _extract_one() so the revalidation runs for single-member extraction as well and not only for extractall() - CVE-2026-6019: percent-encode the cookie value embedded in the http.cookies Morsel.js_output() script snippet and decode it with decodeURIComponent() to prevent breaking out of the script element while keeping UTF-8 values intact
Updated packages:
  • alt-python310-3.10.20-9.el9.x86_64.rpm
    sha:81e8a63efcac1ae1f0118e9d99427025a18e7e96ddfb38fcf64bb25f8cd4e4b7
  • alt-python310-debug-3.10.20-9.el9.x86_64.rpm
    sha:7b12bacd06eb91f16c7d17aae12998c758987398086bbe9a165c756d701b74d7
  • alt-python310-devel-3.10.20-9.el9.x86_64.rpm
    sha:6ab35c49654d586d9faddf528832bd80dfcbb0a2d806c89c9627287e09ae1fa5
  • alt-python310-idle-3.10.20-9.el9.x86_64.rpm
    sha:56e41337dc8ad53e3c897f7eab9a136d3ad5b21041e01c74bf7306b7e2a72160
  • alt-python310-libs-3.10.20-9.el9.x86_64.rpm
    sha:a9c1fd1901a721c7d182288f0dc5d96d25f93f4359269ab3b4cba918d3e855f9
  • alt-python310-test-3.10.20-9.el9.x86_64.rpm
    sha:f6708d78e22191bf18bcd7eb66125e9378a7bd67097d62e6a78b6e92d04a334c
  • alt-python310-tkinter-3.10.20-9.el9.x86_64.rpm
    sha:78d7bf6600f568048ebad419f47aa8250b7b6d764db860e643dee2d78d5ee240
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.