[CLSA-2026:1777385087] alt-python36: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-04-28 14:04:53 UTC
Description:
- CVE-2024-0450: zipfile raises BadZipFile on quoted-overlap archive entries to prevent high-ratio zip bombs - CVE-2026-6100: use-after-free in lzma/bz2 decompressors when a MemoryError leaves a stale next_in pointer on a re-used decompressor
Updated packages:
  • alt-python36-3.6.15-21.el10.x86_64.rpm
    sha:c0014518c843aed0dbfdda0cee55fada703138799bfda7e4a2545b12551a8dce
  • alt-python36-debug-3.6.15-21.el10.x86_64.rpm
    sha:6b23f8cdd31b1062a239c9c853d99ea07fe764d991c10b37ea31ebc5710d7fb5
  • alt-python36-devel-3.6.15-21.el10.x86_64.rpm
    sha:779b99a8dc4e1c8bc2c966303784bbd3fac33a4dacc2d985c44d3ae218ace5f0
  • alt-python36-libs-3.6.15-21.el10.x86_64.rpm
    sha:71731bc4788996710bbceeae79a06180654a4d3107daf5abadffa4d30b5198cd
  • alt-python36-test-3.6.15-21.el10.x86_64.rpm
    sha:e3ae45f8a3a0b3fdbab00a123e96453d7cbebdf4de483f6f0669b2e164df8af8
  • alt-python36-tkinter-3.6.15-21.el10.x86_64.rpm
    sha:4626f4b38dae536f2078f0079a3da1888b976238e43737db28a85a8faadf5108
  • alt-python36-tools-3.6.15-21.el10.x86_64.rpm
    sha:3888b4476f373807e38a8d89381f1a9fb5c2f2a96b270a8d6a2e8b6f1637bbdd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.