[CLSA-2026:1780504338] Fix of 12 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-05 10:48:56 UTC
Description:
* SECURITY UPDATE: tarfile applied AREGTYPE -> DIRTYPE normalization even during multi-block GNU long members (GNUTYPE_LONGNAME / GNUTYPE_LONGLINK), enabling a parsing differential vs. other tar implementations. - debian/patches/CVE-2025-13462.patch: backport of cpython 42d754e3 (gh-143934, Seth Larson + Eashwar Ranganathan). Threads a dircheck flag through frombuf / fromtarfile so normalization is skipped on the inner header during GNU long name / link handling. - CVE-2025-13462 * SECURITY UPDATE: wsgiref.headers.Headers did not reject control characters in header names / values, allowing HTTP header injection from WSGI applications. - debian/patches/CVE-2026-0865.patch: combined backport of cpython f7fceed7 (gh-143917) which adds the control-char regex check, 66da7bf6 (gh-143916 HTAB follow-up) which splits the check so HTAB is allowed in header values (RFC 9110 Section 5.5) but still rejected in header names, plus d931725b (gh-144370) which disallows control characters in status in wsgiref.handlers.start_response. - CVE-2026-0865 * SECURITY UPDATE: http.client did not reject CR/LF in HTTPConnection CONNECT tunnel host / per-tunnel-header values, enabling request injection through a proxy tunnel. - debian/patches/CVE-2026-1502.patch: backport of cpython 05ed7ce7 + b1cf9016 (gh-146212, Seth Larson). Adapted to 3.6's per-line self.send() form (no headers=[] list in _tunnel until 3.9+). Validates _tunnel_host and per-header name / value in _tunnel(). - CVE-2026-1502 * SECURITY UPDATE: http.cookies.Morsel.js_output() emitted an inline intact, enabling HTML injection when a cookie value contains . - debian/patches/CVE-2026-6019.patch: backport of cpython 76b3923d (gh-148848, Seth Larson). Base64-encodes the cookie value and emits document.cookie = atob("...") instead of pasting the raw cookie string into the JavaScript snippet. Composes on top of CVE-2026-3644's js_output() control-character recheck (preserved). - CVE-2026-6019
Updated packages:
  • alt-python36_3.6.15-37_amd64.deb
    sha:6593c6cab05e6217aa210fcad96ccf426f35319b
  • alt-python36-debug_3.6.15-37_amd64.deb
    sha:5965102e92bf6b125c657977e051fde78eddbbda
  • alt-python36-devel_3.6.15-37_amd64.deb
    sha:c0e5bf2498e2d63637d2a4055cdc2651c303b3cd
  • alt-python36-libs_3.6.15-37_amd64.deb
    sha:39cb869155bb08b4df92665920d5a4046f9f15dc
  • alt-python36-test_3.6.15-37_amd64.deb
    sha:8d305a699433631a59eece4df5007ebc1a0926cc
  • alt-python36-tkinter_3.6.15-37_amd64.deb
    sha:6d38a9ba6a3989b600a8b737d52fa2b653778da5
  • alt-python36-tools_3.6.15-37_amd64.deb
    sha:cfc9efe3fbe0e910dc9ae5f34884c08d118a6961
  • alt-python36_3.6.15-37_arm64.deb
    sha:ab82e07be5ac0b7b9fde0e15b4e848cad8ebf819
  • alt-python36-debug_3.6.15-37_arm64.deb
    sha:191c1b80c5d6f45d3ebfe4dbba80271bcb08e525
  • alt-python36-devel_3.6.15-37_arm64.deb
    sha:069601ec1954935fd950de6c1d70a91377411c80
  • alt-python36-libs_3.6.15-37_arm64.deb
    sha:ecdff1fb03bbe20cd86de28e521f16230adc44f2
  • alt-python36-test_3.6.15-37_arm64.deb
    sha:cbe579075096a58d4b660f6a6db3730ceee7c666
  • alt-python36-tkinter_3.6.15-37_arm64.deb
    sha:5a82ff8eb693e04f2033a0bc4589134f2380dd8e
  • alt-python36-tools_3.6.15-37_arm64.deb
    sha:5a3093297183e8184770f6c4c045d0322eeb7cb0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.