[CLSA-2026:1785327660] Fix of 8 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-29 12:21:16 UTC
Description:
* SECURITY UPDATE: configparser key/value injection via CR/CRLF - debian/patches/CVE-2026-0864.patch: normalize CR, CRLF and LF line endings when writing multi-line values in RawConfigParser so a carriage return cannot inject additional keys into the output. - CVE-2026-0864 * SECURITY UPDATE: http.client proxy CONNECT tunnel header injection - debian/patches/CVE-2026-1502.patch: reject CR/LF in the proxy tunnel host and in set_tunnel() custom headers before writing the CONNECT request. - CVE-2026-1502 * SECURITY UPDATE: unicodedata.normalize() quadratic-time DoS - debian/patches/CVE-2026-3276.patch: replace the O(n^2) canonical ordering insertion sort with a counting sort for long combining runs to prevent CPU-exhaustion on crafted input. - CVE-2026-3276 * SECURITY UPDATE: http.cookies js_output() script injection (XSS) - debian/patches/CVE-2026-6019.patch: percent-encode the cookie value embedded in the inline sequence cannot break out. - CVE-2026-6019 * SECURITY UPDATE: tarfile data filter path traversal - debian/patches/CVE-2026-7774.patch: validate the written link target against the extraction root in the data/tar filter. - CVE-2026-7774 * SECURITY UPDATE: ftplib.ftpcp() data-connection SSRF - debian/patches/CVE-2026-8328.patch: apply the CVE-2021-4189 PASV peer-address check to ftpcp() so a malicious source server cannot redirect the target's data connection. - CVE-2026-8328 * SECURITY UPDATE: tarfile hardlink-extraction symlink escape - debian/patches/CVE-2026-11940.patch: pre-validate the symlink at the hardlink's own name in the extraction-filter fallback to prevent a path-traversal escape (incomplete fix of CVE-2025-4330). - CVE-2026-11940 * SECURITY UPDATE: tarfile stream-seek infinite-loop DoS - debian/patches/CVE-2026-11972.patch: break out of _Stream.seek() on EOF so a truncated stream archive cannot cause an unbounded loop. - CVE-2026-11972
Updated packages:
  • alt-python311_3.11.15-5_amd64.deb
    sha:96cc14944332dcec4d28193c8345ce47d9fcbd1b
  • alt-python311-debug_3.11.15-5_amd64.deb
    sha:4a47c6a94770a9deb5fa182016d14285b6f8e76a
  • alt-python311-devel_3.11.15-5_amd64.deb
    sha:304c365aa4ffdf338b910c5959b82cb5928ce753
  • alt-python311-idle_3.11.15-5_amd64.deb
    sha:0bed34ecb4536015fa79c1e09b3d5e942ef8e76c
  • alt-python311-libs_3.11.15-5_amd64.deb
    sha:794f4fa1e56ef614c280507ccdc327bb07c2e0d7
  • alt-python311-test_3.11.15-5_amd64.deb
    sha:9672cab7b66f115c3d536e55075f1d96ec354b1c
  • alt-python311-tkinter_3.11.15-5_amd64.deb
    sha:0505a5b417d83c0828a6dd56b8cbf38244696e6a
  • alt-python311_3.11.15-5_arm64.deb
    sha:ae148a0349a4e932b3fadd68edaee9f23f03462d
  • alt-python311-debug_3.11.15-5_arm64.deb
    sha:063b76fe7ab95c1f85d2e8fe5a4b6a05d6635aa2
  • alt-python311-devel_3.11.15-5_arm64.deb
    sha:fe868a09f7309bc2c15750f6dd4997e0e66fb97c
  • alt-python311-idle_3.11.15-5_arm64.deb
    sha:686c36bd1f952371d3fbc6aaa2f367c73ae08a1e
  • alt-python311-libs_3.11.15-5_arm64.deb
    sha:e23b336e3daa18f2e84bc276be61295ab438a084
  • alt-python311-test_3.11.15-5_arm64.deb
    sha:3eee94ee5f1512d7f6de4414c6075bdf10c74eb0
  • alt-python311-tkinter_3.11.15-5_arm64.deb
    sha:35d3c5b9317eb314327c6f798a67a814834dd8c1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.