Release date:
2026-09-23 16:03:15 UTC
Description:
- ALTPYTH-617: Update to 3.11.16 version
- Drop patches absorbed by upstream 3.11.16: 06003-ssl-use-bio_eof-for-asn1-cadata-eof,
CVE-2025-13462, CVE-2026-0864, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224,
CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-6879, CVE-2026-7774,
CVE-2026-8328, CVE-2026-9669, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-41080
- Keep CVE-2026-7210, reduced to Modules/pyexpat.c: upstream's 16-byte Expat hash salt is
gated on the libexpat HEADER version (XML_COMBINED_VERSION >= 20800), but ELS libexpat
backports XML_SetHashSalt16Bytes into 2.2.x/2.5.x without bumping its version macros, so
that gate is false and CPython would silently fall back to the 8-byte salt on el8, el9,
debian10, ubuntu18.04 and ubuntu20.04. The patch restores the weak-symbol check on the
function's address. No-op where the header really is 2.8.0+ (el7 and ubuntu16.04 use the
bundled libexpat, now 2.8.3; debian13's system libexpat is 2.8.3)
Updated packages:
-
alt-python311-3.11.16-1.el8.x86_64.rpm
sha:5779bb835a4b757b7ed5339cbd080f4d6e4a01d02791d2487c3c093d34306b5c
-
alt-python311-debug-3.11.16-1.el8.x86_64.rpm
sha:7194e64c435dfc729139cf2248196803efc0f4796643a929d4d2b59c8f2caa9b
-
alt-python311-devel-3.11.16-1.el8.x86_64.rpm
sha:34b750bbb381e3bcbe29d17242f5ead1865530627e7c438b2353cb04efaee92d
-
alt-python311-idle-3.11.16-1.el8.x86_64.rpm
sha:61fb7eb20a015a2ac6a04c2790caebc3d69b5ea2c961832a9961a5cd9064db31
-
alt-python311-libs-3.11.16-1.el8.x86_64.rpm
sha:de390f90eddc85370e917e42352803f363219e862c9a7ab2265a41a8d74cbce8
-
alt-python311-test-3.11.16-1.el8.x86_64.rpm
sha:e2c9db507c9656516614932f17e0b16c134185d1d87a95147036ef08e6992162
-
alt-python311-tkinter-3.11.16-1.el8.x86_64.rpm
sha:fc8b52e8498bb8e9fb745f9bbcfa2c23f6ba590ed58177e9bf359654de55f6ef
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.