[CLSA-2026:1790179215] alt-python311: Fix of CVE-2026-2297
Type:
security
Severity:
Low
Release date:
2026-09-23 16:00:28 UTC
Description:
- ALTPYTH-617: Update to 3.11.16 version - Drop patches absorbed by upstream 3.11.16: 06003-ssl-use-bio_eof-for-asn1-cadata-eof, CVE-2025-13462, CVE-2026-0864, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224, CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-6879, CVE-2026-7774, CVE-2026-8328, CVE-2026-9669, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-41080 - Keep CVE-2026-7210, reduced to Modules/pyexpat.c: upstream's 16-byte Expat hash salt is gated on the libexpat HEADER version (XML_COMBINED_VERSION >= 20800), but ELS libexpat backports XML_SetHashSalt16Bytes into 2.2.x/2.5.x without bumping its version macros, so that gate is false and CPython would silently fall back to the 8-byte salt on el8, el9, debian10, ubuntu18.04 and ubuntu20.04. The patch restores the weak-symbol check on the function's address. No-op where the header really is 2.8.0+ (el7 and ubuntu16.04 use the bundled libexpat, now 2.8.3; debian13's system libexpat is 2.8.3)
CVEs fixed:
Updated packages:
  • alt-python311-3.11.16-1.el7.x86_64.rpm
    sha:4faadec4c618d1d3ddcbe65d238f3243319f92d6135b8c0ba34ef5e08631f1dc
  • alt-python311-debug-3.11.16-1.el7.x86_64.rpm
    sha:fff8762f3f54ff495298ad5398f581ed1a065e66896d6593186440b9c9d047dd
  • alt-python311-devel-3.11.16-1.el7.x86_64.rpm
    sha:fcd62f8dbeb8717ad608450cea0465986cee156f127c60b0de548b4fa8220a42
  • alt-python311-idle-3.11.16-1.el7.x86_64.rpm
    sha:3f46c26dac9197c3a1647487f0ae677330c4ba09d8774425f49acab2946a9947
  • alt-python311-libs-3.11.16-1.el7.x86_64.rpm
    sha:b319bc373272ec081db1c5b0defefa19e9ce6d6466442c1dd3565aaa2002b733
  • alt-python311-test-3.11.16-1.el7.x86_64.rpm
    sha:c82808c324909df633eed7f048bd50ba8d0cbd20ed53d6f3b14580d30585201c
  • alt-python311-tkinter-3.11.16-1.el7.x86_64.rpm
    sha:b0c570d38bf6d220b0693336c76587ea858058523c060be8d604022f3c8181b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.