[CLSA-2026:1777387409] alt-python36: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-04-28 17:31:47 UTC
Description:
- CVE-2024-0450: zipfile raises BadZipFile on quoted-overlap archive entries to prevent high-ratio zip bombs - CVE-2026-6100: use-after-free in lzma/bz2 decompressors when a MemoryError leaves a stale next_in pointer on a re-used decompressor
Updated packages:
  • alt-python36-3.6.15-21.el8.x86_64.rpm
    sha:19a6e19fc662d47b68a4debcfffc189b6b22f77e3052b520801163bd05576f5a
  • alt-python36-debug-3.6.15-21.el8.x86_64.rpm
    sha:5d235ae1a804131d6aa60a28051ef388b0f78cff7ed224005eb61d4823b1290b
  • alt-python36-devel-3.6.15-21.el8.x86_64.rpm
    sha:107c4d44a16213e0dd473cbd405cb3e7c07e97149d8f6d64db5ca5583e070b79
  • alt-python36-libs-3.6.15-21.el8.x86_64.rpm
    sha:8b2e127e0b5be15d6739d78ead92283a6c06e840281a2d741444104213e8551d
  • alt-python36-test-3.6.15-21.el8.x86_64.rpm
    sha:af8611ad6f7cad6106d33ede88b36d4f0efa81d230f5b734fab6b24a7c7f98b0
  • alt-python36-tkinter-3.6.15-21.el8.x86_64.rpm
    sha:90f23a1c12c21642d28458362b0a478503fbeac4fcbe92dbd28021c7915dfe4d
  • alt-python36-tools-3.6.15-21.el8.x86_64.rpm
    sha:a9d3181e2dc855475ae83d72956254562fe37304f52f41e44afcade9c40e8191
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.