[CLSA-2026:1786551874] alt-python36: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 16:24:48 UTC
Description:
- CVE-2026-7774: tarfile: fix data_filter bypass via crafted link entries; validate the normalised link target that is actually written to disk, resolve symlink targets relative to the member name with trailing separators stripped, and reject link members (including symlinks with empty or directory-like names) that would replace the destination directory itself and redirect later members outside it - CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to ftpcp(): use the source server's real peer address instead of the attacker-controllable IPv4 address from the PASV reply unless trust_server_pasv_ipv4_address is set
Updated packages:
  • alt-python36-3.6.15-34.el10.x86_64.rpm
    sha:e00ea30372bbfed5f2e1032c270ea4619a4700dc7fb958903f6ef10d690594c7
  • alt-python36-debug-3.6.15-34.el10.x86_64.rpm
    sha:58e1dc45c0a818b34dcd5912b2b9c36b626ff11d93b4d7699de99d23a93392a7
  • alt-python36-devel-3.6.15-34.el10.x86_64.rpm
    sha:6b9ef41696d10cb63545dfec23be73094cf095dbe3cff23d9cdedbeb192cd63f
  • alt-python36-libs-3.6.15-34.el10.x86_64.rpm
    sha:598b637a939e6709b4a09fe2dc4b362826595537e965e22d613b1ad6cba5c952
  • alt-python36-test-3.6.15-34.el10.x86_64.rpm
    sha:fd7fc227814b4528bb4b1f631be184a7f16b74c5a38a2172ea185b002f96b30b
  • alt-python36-tkinter-3.6.15-34.el10.x86_64.rpm
    sha:f0feda601a6025c130c0df862b8be19d2d28cc7c092a57b2bc679a8d9d616c58
  • alt-python36-tools-3.6.15-34.el10.x86_64.rpm
    sha:f44e18b9b8bf621f958bc8f562f1e9589b81b67a4b21909819243e83a64bc98f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.