[CLSA-2026:1790179042] Fix CVE(s): CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 15:57:35 UTC
Description:
* ALTPYTH-616: Update to 3.10.21 * Drop CVE backports included in upstream 3.10.21: CVE-2026-3644, CVE-2026-4224, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-9669, CVE-2026-41080, CVE-2026-15308, CVE-2025-13462, CVE-2026-8328, CVE-2026-7774, CVE-2026-1502, CVE-2026-3276, CVE-2026-0864, CVE-2026-11972, CVE-2026-11940, CVE-2026-6879 * debian/patches/CVE-2026-7210.patch: re-anchor the Include/pyexpat.h hunk onto the 3.10.21 PyExpat_CAPI layout, which inserted the SetBillionLaughsAttackProtection* members before the end-of-struct sentinel, so the patch applies with --fuzz=0 instead of relying on the builder's --fuzz=2. No functional change: the new SetHashSalt16Bytes member still lands last in the struct (the expat >= 2.4.0 runtime requirement added on the RPM side is not needed here -- Debian/Ubuntu builds use --without-system-expat)
CVEs fixed:
Updated packages:
  • alt-python310_3.10.21-1_amd64.deb
    sha:c62beec65597ffc7e3be14630fa83657722e3544
  • alt-python310-debug_3.10.21-1_amd64.deb
    sha:59d3465dd762ef018fdf654af86a02f168371032
  • alt-python310-devel_3.10.21-1_amd64.deb
    sha:547db4254e7f0014501c25d636f6cefc3690c48a
  • alt-python310-idle_3.10.21-1_amd64.deb
    sha:077337eaeb054507224351483b54cb23fccb94e4
  • alt-python310-libs_3.10.21-1_amd64.deb
    sha:a6bdd01c3b7da52cccf7c99b7b47b1b1580ef91f
  • alt-python310-test_3.10.21-1_amd64.deb
    sha:d61f5fa5e4b165817a130f583aaced7ff5a2143c
  • alt-python310-tkinter_3.10.21-1_amd64.deb
    sha:890c4f8de7ca46b4acb9012b6c107942168cfa5d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.