[CLSA-2026:1785423110] Fix CVE(s): CVE-2025-12781
Type:
security
Severity:
Moderate
Release date:
2026-07-30 14:52:01 UTC
Description:
* SECURITY UPDATE: base64.b64decode() and urlsafe_b64decode() always accepted the standard-alphabet '+' and '/' characters even when an alternative alphabet excluding them was specified via altchars, so malformed input could bypass strict-alphabet validation filters (CWE-704: incorrect type conversion or cast, per NVD). - debian/patches/CVE-2025-12781.patch: backport of cpython 9060b4ab (gh-125346, PR gh-141128; adapted from the reviewed alt-python37 backport). Emits DeprecationWarning/FutureWarning when '+' or '/' appear outside the alternative alphabet; decoded output unchanged. - CVE-2025-12781
CVEs fixed:
Updated packages:
  • alt-python39_3.9.23-23_amd64.deb
    sha:85f052683bfd1187b04a32aff1efea2995c99bff
  • alt-python39-debug_3.9.23-23_amd64.deb
    sha:3dc59b9d12eb66f8f28061f6d46bdb1264c89201
  • alt-python39-devel_3.9.23-23_amd64.deb
    sha:b45fe87775dff98ab1918491958558254ded2bb7
  • alt-python39-idle_3.9.23-23_amd64.deb
    sha:a58ec81711131b5a71763831a43267375c613527
  • alt-python39-libs_3.9.23-23_amd64.deb
    sha:dc43efe06c2f98837a9bfb7e445275c6b9f1f1f6
  • alt-python39-test_3.9.23-23_amd64.deb
    sha:10b579fa5c26ac5d81b0f97c704a824f5af37acc
  • alt-python39-tkinter_3.9.23-23_amd64.deb
    sha:21918c270dd41e9aed28b1d360186a45f02b4911
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.