[CLSA-2026:1785341584] alt-python311: Fix of 8 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-29 16:13:20 UTC
Description:
- CVE-2026-0864: normalize CR/CRLF line endings in configparser writes to prevent key/value injection - CVE-2026-1502: reject CR/LF in http.client proxy CONNECT tunnel host and headers - CVE-2026-3276: fix O(n^2) canonical ordering in unicodedata.normalize() (DoS on crafted combining sequences) - CVE-2026-6019: percent-encode cookie values embedded in http.cookies js_output() to prevent script injection (XSS) - CVE-2026-7774: validate written link target in tarfile data filter to prevent path traversal - CVE-2026-8328: apply CVE-2021-4189 PASV peer-address check to ftplib.ftpcp() to prevent data-connection SSRF - CVE-2026-11940: fix symlink escape via tarfile hardlink-extraction fallback (path traversal) - CVE-2026-11972: make tarfile._Stream.seek() break at EOF to prevent infinite-loop DoS on crafted stream archives
Updated packages:
  • alt-python311-3.11.15-5.el10.x86_64.rpm
    sha:347a5c6617ba60d4d6f14e12cf42c6669fc40e573cea55a40bfeb2ad1012c55f
  • alt-python311-debug-3.11.15-5.el10.x86_64.rpm
    sha:a620d72ca502bb2046ecc858fa3bed7eaad0c70236eca9ab7ee914a944725ecb
  • alt-python311-devel-3.11.15-5.el10.x86_64.rpm
    sha:246e590fdc6e4bee2a89ba8f2157659197b4c4423a0de3d0d2fc055368f56f4b
  • alt-python311-idle-3.11.15-5.el10.x86_64.rpm
    sha:11baa091e98294a908d92fba577e077bd27ff894743a04ce6fb8e7404e067632
  • alt-python311-libs-3.11.15-5.el10.x86_64.rpm
    sha:a591b5d71187112b9194f9bdac652d0a250fb861c54c4c330a936b6784332fcc
  • alt-python311-test-3.11.15-5.el10.x86_64.rpm
    sha:7bf11d6b8be9ca9b7bda40f2c49b53f2ec39d53012640791e49eeb2927e1f7d0
  • alt-python311-tkinter-3.11.15-5.el10.x86_64.rpm
    sha:2ba4875a90eaaf4201734af193a0f69638dc5b27334345d608dd515637be3efa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.