[CLSA-2026:1786555626] alt-python36: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 17:27:19 UTC
Description:
- CVE-2026-7774: tarfile: fix data_filter bypass via crafted link entries; validate the normalised link target that is actually written to disk, resolve symlink targets relative to the member name with trailing separators stripped, and reject link members (including symlinks with empty or directory-like names) that would replace the destination directory itself and redirect later members outside it - CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to ftpcp(): use the source server's real peer address instead of the attacker-controllable IPv4 address from the PASV reply unless trust_server_pasv_ipv4_address is set
Updated packages:
  • alt-python36-3.6.15-34.el8.x86_64.rpm
    sha:ee3607e3b79bf11bdc3d810bfb67e92118e091b6b5a988d2c46fb78fbc596c0b
  • alt-python36-debug-3.6.15-34.el8.x86_64.rpm
    sha:59c8fa6f6f71327217a82816536eb1fafb68cd8fe6b1bcd04e3ad54f9d7fe0f2
  • alt-python36-devel-3.6.15-34.el8.x86_64.rpm
    sha:04e932e34df4a85b78dc314ee8edef000b06eb821feee3b7ac0f1e4730f371db
  • alt-python36-libs-3.6.15-34.el8.x86_64.rpm
    sha:bbc874c99079b325f449acc022e9225910d939813d38950ed30fca70c70a4a92
  • alt-python36-test-3.6.15-34.el8.x86_64.rpm
    sha:f2b5185d1b93f16f7df5f7f698b0539c99612695661bd6af7b74dab15dc87d9d
  • alt-python36-tkinter-3.6.15-34.el8.x86_64.rpm
    sha:5b480115cea201b8bafd9e6895c81cc42125724bf24aff4f2b481cbea66bd66a
  • alt-python36-tools-3.6.15-34.el8.x86_64.rpm
    sha:31bd18176bda6dcf8e4c0b17355747255d100f51a2472421752550a49c6a2d04
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.