[CLSA-2026:1785339313] alt-python311: Fix of 8 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-29 15:35:32 UTC
Description:
- CVE-2026-0864: normalize CR/CRLF line endings in configparser writes to prevent key/value injection - CVE-2026-1502: reject CR/LF in http.client proxy CONNECT tunnel host and headers - CVE-2026-3276: fix O(n^2) canonical ordering in unicodedata.normalize() (DoS on crafted combining sequences) - CVE-2026-6019: percent-encode cookie values embedded in http.cookies js_output() to prevent script injection (XSS) - CVE-2026-7774: validate written link target in tarfile data filter to prevent path traversal - CVE-2026-8328: apply CVE-2021-4189 PASV peer-address check to ftplib.ftpcp() to prevent data-connection SSRF - CVE-2026-11940: fix symlink escape via tarfile hardlink-extraction fallback (path traversal) - CVE-2026-11972: make tarfile._Stream.seek() break at EOF to prevent infinite-loop DoS on crafted stream archives
Updated packages:
  • alt-python311-3.11.15-5.el7.x86_64.rpm
    sha:b822c1a5ca02ef5c060f90bc401d28bf4e9d95dfc3e78e06861a7bf2fc1898c9
  • alt-python311-debug-3.11.15-5.el7.x86_64.rpm
    sha:f4adfe3e321ace80407cc1e6f5a8249bb32cfed977f632168463bcfa5439618a
  • alt-python311-devel-3.11.15-5.el7.x86_64.rpm
    sha:c332cfd04f611ff86f0dc3439b6ae797c6e2b83400e994426342f8bf87b0e1cb
  • alt-python311-idle-3.11.15-5.el7.x86_64.rpm
    sha:43eff2def3c45a16e8e2e6cf1cd1477c1e6f462115e5ca5afc6aeaa924146855
  • alt-python311-libs-3.11.15-5.el7.x86_64.rpm
    sha:993bf821c984ada623fd322d9ab3e97aa8b869de8c93e2ed96d503d6620efc94
  • alt-python311-test-3.11.15-5.el7.x86_64.rpm
    sha:9459d1554b82f33a7c1c9557f168dd4870890d485e8b08d40f7966b32e86fb9a
  • alt-python311-tkinter-3.11.15-5.el7.x86_64.rpm
    sha:4c659510c9024f43a1136587f2e090e1d2e02c0b41b8d4e1d804310b0dc7ca27
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.