[CLSA-2026:1789782378] python: Fix of CVE-2026-9669
Type:
security
Severity:
Important
Release date:
2026-09-19 01:46:29 UTC
Description:
- CVE-2026-9669: latch the libbz2 error code in BZ2Decomp_decompress() and raise ValueError on any later decompress() call, so a BZ2Decompressor that already failed cannot re-enter BZ2_bzDecompress(); make the same error sticky for the C BZ2File read paths via a new Util_BzRead() wrapper, so a retried read()/readline() re-reports the original IOError instead of re-entering BZ2_bzDecompress() on the errored stream
CVEs fixed:
Updated packages:
  • python-2.7.18-1.amzn2.0.22.tuxcare.els3.x86_64.rpm
    sha:67758a12041f7d30ce41f3cee369e1eb936061b08da6ed7c957316f1e9b2d8eb
  • python-debug-2.7.18-1.amzn2.0.22.tuxcare.els3.x86_64.rpm
    sha:a95bb47ccaa69d52d88acd0c4d7816bc44d0fae4fb567b678949fdd2102f38d7
  • python-devel-2.7.18-1.amzn2.0.22.tuxcare.els3.x86_64.rpm
    sha:3f613df7b5227663c602ce1b618c73f1638a97c6b387decbc407e3564097b02f
  • python-libs-2.7.18-1.amzn2.0.22.tuxcare.els3.i686.rpm
    sha:6b4cb327a7c7eac5bd30aaefaa5120202f5eadc0ef7c728b15b4ffd8df61a9f4
  • python-libs-2.7.18-1.amzn2.0.22.tuxcare.els3.x86_64.rpm
    sha:3714c534e2c69099023b75449a13dfd430ba698cce3dcb568540dfebddadf3b2
  • python-test-2.7.18-1.amzn2.0.22.tuxcare.els3.x86_64.rpm
    sha:ec87da441d9410bc96ea7d87df7257659ab9a8bf17a89bef68a065914ed9825b
  • python-tools-2.7.18-1.amzn2.0.22.tuxcare.els3.x86_64.rpm
    sha:957d0c51a961109d6f6fde82a786cff0f213ec34620ba8476caddcc16e35958b
  • tkinter-2.7.18-1.amzn2.0.22.tuxcare.els3.x86_64.rpm
    sha:c123909dd8920a4ac46b09a5ad3f13da2a5c7a16cd5241b75809d7f7f2e37847
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.