[CLSA-2026:1790171835] alt-python310: Fix of CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 13:57:25 UTC
Description:
- ALTPYTH-616: Update to 3.10.21 - Drop 06003-ssl-use-bio_eof-for-asn1-cadata-eof.patch, included in upstream 3.10.21 - Drop CVE backports included in upstream 3.10.21: CVE-2026-3644, CVE-2026-4224, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-9669, CVE-2026-41080, CVE-2026-15308, CVE-2025-13462, CVE-2026-8328, CVE-2026-7774, CVE-2026-1502, CVE-2026-3276, CVE-2026-0864, CVE-2026-11972, CVE-2026-11940, CVE-2026-6879 - Require expat >= 2.4.0 on rhel > 7: 3.10.21 calls XML_SetBillionLaughsAttackProtectionActivationThreshold and ...MaximumAmplification, which are required (non-weak) symbols in pyexpat. libexpat has no symbol versioning, so RPM records only libexpat.so.1()(64bit) and cannot derive the floor; on an older expat the package installs and then fails at import with "undefined symbol". CL7 keeps the bundled expat - Re-anchor the Include/pyexpat.h hunk of CVE-2026-7210.patch onto the 3.10.21 PyExpat_CAPI layout (3.10.21 inserted the SetBillionLaughsAttackProtection* members before the end-of-struct sentinel) so it applies with --fuzz=0
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-1.el9.x86_64.rpm
    sha:c724df9aee59208cdf3ac34fb461dc38e089bb7fb0b9e27d664c9ee96aefbeff
  • alt-python310-debug-3.10.21-1.el9.x86_64.rpm
    sha:8908f2b44c41b428b901753282a588167a6c12dc8d473662134f6213a6705de1
  • alt-python310-devel-3.10.21-1.el9.x86_64.rpm
    sha:06c35e41986ea8f01d70aacb140de84872effafb80cb1cf513dabc123f11ae41
  • alt-python310-idle-3.10.21-1.el9.x86_64.rpm
    sha:78576c4bd15f3647abe4aceab499058f4d37522b4e3ec8fa0350e918752080be
  • alt-python310-libs-3.10.21-1.el9.x86_64.rpm
    sha:0f1e61b6edcd3fd8bed34405b06bde343db5a6f6119eaa21cced70d2c4ddae60
  • alt-python310-test-3.10.21-1.el9.x86_64.rpm
    sha:d6100860d7de0f41c47d46b7686fe0a8c827f04f39bbb641ee39a76e1d95d0b1
  • alt-python310-tkinter-3.10.21-1.el9.x86_64.rpm
    sha:e1a4966f0406d42525faac2efbcb862a1f2f93de509136eeb6f142e78d48ccf6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.