[CLSA-2026:1790172514] Fix CVE(s): CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 14:08:45 UTC
Description:
* ALTPYTH-617: Update to 3.11.16 version * Drop patches absorbed by upstream 3.11.16: CVE-2025-13462, CVE-2026-0864, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224, CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-6879, CVE-2026-7774, CVE-2026-8328, CVE-2026-9669, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-41080 * Keep CVE-2026-7210, reduced to Modules/pyexpat.c: upstream gates the 16-byte Expat hash salt on the libexpat HEADER version (XML_COMBINED_VERSION >= 20800), but ELS libexpat backports XML_SetHashSalt16Bytes into 2.2.x/2.5.x without bumping its version macros, so that gate is false and CPython would silently fall back to the 8-byte salt on debian10, ubuntu18.04 and ubuntu20.04. The patch restores the weak-symbol check on the function's address. No-op on ubuntu16.04 (bundled libexpat, now 2.8.3) and debian13 (system libexpat 2.8.3). - debian/patches/CVE-2026-7210.patch
CVEs fixed:
Updated packages:
  • alt-python311_3.11.16-1_amd64.deb
    sha:1d5ebd1300ad1b68f480ff1a3e05fa28919bd302
  • alt-python311-debug_3.11.16-1_amd64.deb
    sha:6da0cc6c46bb05518429da7b3011d3c5caf0d1c0
  • alt-python311-devel_3.11.16-1_amd64.deb
    sha:8f66191c0af8fca27eb731d9939894dd12009328
  • alt-python311-idle_3.11.16-1_amd64.deb
    sha:8172b097889fee828c6578e8ca2b57372ab314a1
  • alt-python311-libs_3.11.16-1_amd64.deb
    sha:15fe19196f67bf4e68faeec72a0db818842f4404
  • alt-python311-test_3.11.16-1_amd64.deb
    sha:b3a7bb47eff2d5eae810086e21a4885aa8ace766
  • alt-python311-tkinter_3.11.16-1_amd64.deb
    sha:9a71aaf33f90726e9b913859c2100151a0697a5b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.