[CLSA-2026:1790172350] Fix CVE(s): CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 14:06:01 UTC
Description:
* ALTPYTH-617: Update to 3.11.16 version * Drop patches absorbed by upstream 3.11.16: CVE-2025-13462, CVE-2026-0864, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224, CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-6879, CVE-2026-7774, CVE-2026-8328, CVE-2026-9669, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-41080 * Keep CVE-2026-7210, reduced to Modules/pyexpat.c: upstream gates the 16-byte Expat hash salt on the libexpat HEADER version (XML_COMBINED_VERSION >= 20800), but ELS libexpat backports XML_SetHashSalt16Bytes into 2.2.x/2.5.x without bumping its version macros, so that gate is false and CPython would silently fall back to the 8-byte salt on debian10, ubuntu18.04 and ubuntu20.04. The patch restores the weak-symbol check on the function's address. No-op on ubuntu16.04 (bundled libexpat, now 2.8.3) and debian13 (system libexpat 2.8.3). - debian/patches/CVE-2026-7210.patch
CVEs fixed:
Updated packages:
  • alt-python311_3.11.16-1_amd64.deb
    sha:c79f483dded3331d07d74207e22b8c1f88971bf9
  • alt-python311-debug_3.11.16-1_amd64.deb
    sha:6da0cc6c46bb05518429da7b3011d3c5caf0d1c0
  • alt-python311-devel_3.11.16-1_amd64.deb
    sha:443b2e1d3e036964c16e24fc00273e7025ce2728
  • alt-python311-idle_3.11.16-1_amd64.deb
    sha:9abc3c790f4e5ae6c51ca1fc7bd09f8c7f0b23a7
  • alt-python311-libs_3.11.16-1_amd64.deb
    sha:2d00fccaa28401efd466f8bb892a78575ec2e785
  • alt-python311-test_3.11.16-1_amd64.deb
    sha:0f1834257ead9310d861adca842b02fa8a685f29
  • alt-python311-tkinter_3.11.16-1_amd64.deb
    sha:ab05265ac0fd67601befeabc2ec0c38bb8ef52f1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.