[CLSA-2026:1777384579] Fix CVE(s): CVE-2024-0450, CVE-2026-6100
Type:
security
Severity:
Critical
Release date:
2026-04-28 13:56:25 UTC
Description:
* SECURITY UPDATE: zipfile quoted-overlap zip bomb - debian/patches/CVE-2024-0450.patch: raise BadZipFile when an archive entry overlaps with another entry or the central directory, preventing quoted-overlap zip bombs with extreme compression ratios. - CVE-2024-0450 * SECURITY UPDATE: use-after-free in lzma/bz2 decompressors - debian/patches/CVE-2026-6100.patch: null next_in at the error: label of decompress() in Modules/_bz2module.c and Modules/_lzmamodule.c so the decompressor cannot be re-used with a stale buffer pointer after a MemoryError. - CVE-2026-6100
Updated packages:
  • alt-python36_3.6.15-30_amd64.deb
    sha:425decbff607aadb8179680d3a5e31d875bc79c5
  • alt-python36-debug_3.6.15-30_amd64.deb
    sha:e9901a969ece7b5176fe362fe4a94094b03e65bb
  • alt-python36-devel_3.6.15-30_amd64.deb
    sha:34c02e07360cee55a9c7233c7f614ef6f726794e
  • alt-python36-libs_3.6.15-30_amd64.deb
    sha:1594f21579d180062a3d4d5e2e39b42fd61b94fb
  • alt-python36-test_3.6.15-30_amd64.deb
    sha:8a08caafd19ca824f3ffac79ac1aa012343c22af
  • alt-python36-tkinter_3.6.15-30_amd64.deb
    sha:6db52023ffc095229b79c55c8412141316d95e2f
  • alt-python36-tools_3.6.15-30_amd64.deb
    sha:d1052ceb16579f4a45621b9c5f0a738b96d2b148
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.