[CLSA-2026:1785422452] Fix CVE(s): CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:41:05 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). - debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab (gh-125346, PR gh-141128; adapted from the reviewed alt-python37 backport). Emits DeprecationWarning/FutureWarning when '+' or '/' appear outside the alternative alphabet; decoded output unchanged. - CVE-2025-12781
CVEs fixed:
Updated packages:
  • alt-python39_3.9.23-23_amd64.deb
    sha:e771787822cac6b5af48b42147483996d5d82a7c
  • alt-python39-debug_3.9.23-23_amd64.deb
    sha:3dc59b9d12eb66f8f28061f6d46bdb1264c89201
  • alt-python39-devel_3.9.23-23_amd64.deb
    sha:12354c4bf5c5c6e9b1d3e6b4d1bb6d67c04b4da4
  • alt-python39-idle_3.9.23-23_amd64.deb
    sha:c89cdac4e50cf213f63ad9f272ee02cf7c6a3281
  • alt-python39-libs_3.9.23-23_amd64.deb
    sha:9ad5cfbd00eec61bb52b9f2b50abc062dbd594b9
  • alt-python39-test_3.9.23-23_amd64.deb
    sha:ca89be97c4fd72c5e4c4c331c34380516b724cfc
  • alt-python39-tkinter_3.9.23-23_amd64.deb
    sha:211d4ad86515349e76fb37a9df51e45c912247e6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.