[CLSA-2026:1785422795] Fix CVE(s): CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:46:48 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). - debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab (gh-125346, PR gh-141128; adapted from the reviewed alt-python37 backport). Emits DeprecationWarning/FutureWarning when '+' or '/' appear outside the alternative alphabet; decoded output unchanged. - CVE-2025-12781
CVEs fixed:
Updated packages:
  • alt-python39_3.9.23-23_amd64.deb
    sha:414b6c4bdf114c6d89d8973e3ce7dabf402b627a
  • alt-python39-debug_3.9.23-23_amd64.deb
    sha:8c6a65c56e8e250a9d0c24b31fcfc87e0cb37612
  • alt-python39-devel_3.9.23-23_amd64.deb
    sha:25b66f624b4c2e02c9443f6d724a07848e206944
  • alt-python39-idle_3.9.23-23_amd64.deb
    sha:eb4d7192c2aaca1d72adba93bc2cab7da79a79b4
  • alt-python39-libs_3.9.23-23_amd64.deb
    sha:54c80449fb15958f5cd9fed6d15b0517645e9921
  • alt-python39-test_3.9.23-23_amd64.deb
    sha:bb84d5adb5f841eb9a3f78702be78ba7cc37c52b
  • alt-python39-tkinter_3.9.23-23_amd64.deb
    sha:227fac54aaab45ed08802386a0dfdf342015b6fa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.