Release date:
2026-09-23 16:06:11 UTC
Description:
- ALTPYTH-617: Update to 3.11.16 version
- Drop patches absorbed by upstream 3.11.16: 06003-ssl-use-bio_eof-for-asn1-cadata-eof,
CVE-2025-13462, CVE-2026-0864, CVE-2026-1502, CVE-2026-3276, CVE-2026-3644, CVE-2026-4224,
CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6100, CVE-2026-6879, CVE-2026-7774,
CVE-2026-8328, CVE-2026-9669, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308, CVE-2026-41080
- Keep CVE-2026-7210, reduced to Modules/pyexpat.c: upstream's 16-byte Expat hash salt is
gated on the libexpat HEADER version (XML_COMBINED_VERSION >= 20800), but ELS libexpat
backports XML_SetHashSalt16Bytes into 2.2.x/2.5.x without bumping its version macros, so
that gate is false and CPython would silently fall back to the 8-byte salt on el8, el9,
debian10, ubuntu18.04 and ubuntu20.04. The patch restores the weak-symbol check on the
function's address. No-op where the header really is 2.8.0+ (el7 and ubuntu16.04 use the
bundled libexpat, now 2.8.3; debian13's system libexpat is 2.8.3)
Updated packages:
-
alt-python311-3.11.16-1.el9.x86_64.rpm
sha:85824ca4827361dbdc2148b7cf4a0b37980ae613c0263b9dc7ca5736f3de8cbc
-
alt-python311-debug-3.11.16-1.el9.x86_64.rpm
sha:f36e9f03e118ddb5fa021ea0abdf3fc25ab6be69a86753cceee305c7bb97e0cb
-
alt-python311-devel-3.11.16-1.el9.x86_64.rpm
sha:631697923e191f43b8a12a89257dc27e1d6e6306bc030288eec710f706a74525
-
alt-python311-idle-3.11.16-1.el9.x86_64.rpm
sha:ffb3100ce2f869a2b01d63e0075bcef75cb879722fa1ac465c658184d12c9bd9
-
alt-python311-libs-3.11.16-1.el9.x86_64.rpm
sha:c857842a24c608ec5b402ea16f195b46e7c93b7c0c0b471c35f2854f51947d9f
-
alt-python311-test-3.11.16-1.el9.x86_64.rpm
sha:7bdfcffebdf8353a531ec95c2c275958163c1bd0f8ac32cd01aadfa4e47ba4e2
-
alt-python311-tkinter-3.11.16-1.el9.x86_64.rpm
sha:b60216a4d2f74b75037b65e60dbf199bf541a2a0e183946bf4219cf56f282893
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.