[CLSA-2026:1786550896] alt-python36: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 16:08:30 UTC
Description:
- CVE-2026-7774: tarfile: fix data_filter bypass via crafted link entries; validate the normalised link target that is actually written to disk, resolve symlink targets relative to the member name with trailing separators stripped, and reject link members (including symlinks with empty or directory-like names) that would replace the destination directory itself and redirect later members outside it - CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to ftpcp(): use the source server's real peer address instead of the attacker-controllable IPv4 address from the PASV reply unless trust_server_pasv_ipv4_address is set
Updated packages:
  • alt-python36-3.6.15-34.el7.x86_64.rpm
    sha:25d7255bc5cdfd82a393e538e70bd1629f068b06aecaf1c0a74087c4d6617906
  • alt-python36-debug-3.6.15-34.el7.x86_64.rpm
    sha:bbd39c8241324194ea14f0eba430070983e96d0d1915dd38832de2d770e97223
  • alt-python36-devel-3.6.15-34.el7.x86_64.rpm
    sha:61d5d2eb09788aa992a7965407cdd07b430ac96c628aca4f1f9d4876b59e7588
  • alt-python36-libs-3.6.15-34.el7.x86_64.rpm
    sha:b89c737a65b8034c9ff8f717b2e3a6db003b2b4a1e60267a15a4c2998e58fe01
  • alt-python36-test-3.6.15-34.el7.x86_64.rpm
    sha:688cbd30685e7dd9c3ff3be03f521dd5a860593592a4f8dc653bfc380199e085
  • alt-python36-tkinter-3.6.15-34.el7.x86_64.rpm
    sha:7b235706f988d14c454f86c1d3eea2e45d25f214808276306c04b55689ac1da8
  • alt-python36-tools-3.6.15-34.el7.x86_64.rpm
    sha:349a632f32f5953565cac87d5d9b6fa45a40c0daddb88b474839f636c949578d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.