[CLSA-2026:1790172187] alt-python311: Fix of CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 14:03:18 UTC
Description:
- ALTPYTH-617: Update to 3.11.16 version - Drop patches absorbed by upstream 3.11.16: 06003-ssl-use-bio_eof-for-asn1-cadata-eof, CVE-2025-13462, CVE-2026-0864, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224, CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-6879, CVE-2026-7774, CVE-2026-8328, CVE-2026-9669, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-41080 - Keep CVE-2026-7210, reduced to Modules/pyexpat.c: upstream's 16-byte Expat hash salt is gated on the libexpat HEADER version (XML_COMBINED_VERSION >= 20800), but ELS libexpat backports XML_SetHashSalt16Bytes into 2.2.x/2.5.x without bumping its version macros, so that gate is false and CPython would silently fall back to the 8-byte salt on el8, el9, debian10, ubuntu18.04 and ubuntu20.04. The patch restores the weak-symbol check on the function's address. No-op where the header really is 2.8.0+ (el7 and ubuntu16.04 use the bundled libexpat, now 2.8.3; debian13's system libexpat is 2.8.3)
CVEs fixed:
Updated packages:
  • alt-python311-3.11.16-1.el10.x86_64.rpm
    sha:51dbde9de55ff61554a1377d5d0820bb7731408b99c38b2aa348d12fafeaa464
  • alt-python311-debug-3.11.16-1.el10.x86_64.rpm
    sha:5a8bd81fb094d1762e6864a6df0067faeb089dd1cb58b050bc79a0ad2533d019
  • alt-python311-devel-3.11.16-1.el10.x86_64.rpm
    sha:b9b86909c7c05aadd712b2112b57df7e086964250b472b8d23bc65e84eb2911b
  • alt-python311-idle-3.11.16-1.el10.x86_64.rpm
    sha:31132f9d9d7fd908204613e369c3d2c9355f735ab428dc9b4a6d28186ce488e1
  • alt-python311-libs-3.11.16-1.el10.x86_64.rpm
    sha:27bd30671f975976de446e5c36fae549686368c7f9b60e701bd8ca74b4683266
  • alt-python311-test-3.11.16-1.el10.x86_64.rpm
    sha:d31f9b57f69472c958c3ada78255447f043890c89f0b28aab0f9e34fc1eb58b5
  • alt-python311-tkinter-3.11.16-1.el10.x86_64.rpm
    sha:8cc602ac9db9299266ba90324bc72cafb690cef3c5c383ee3b46aef016ffe8e9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.