[CLSA-2026:1777390475] alt-python36: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-04-28 15:34:41 UTC
Description:
- CVE-2024-0450: zipfile raises BadZipFile on quoted-overlap archive entries to prevent high-ratio zip bombs - CVE-2026-6100: use-after-free in lzma/bz2 decompressors when a MemoryError leaves a stale next_in pointer on a re-used decompressor
Updated packages:
  • alt-python36-3.6.15-21.el9.x86_64.rpm
    sha:5a378343b0f6da84f5465508ebe4e17b01ce6eec7f64344c0766c316f5e60053
  • alt-python36-debug-3.6.15-21.el9.x86_64.rpm
    sha:58a6536ab6259beadabaf3a6d207769262734c2c8b34a6f109774a87ea914d33
  • alt-python36-devel-3.6.15-21.el9.x86_64.rpm
    sha:65644ec540d12d12344dfa99068bae5d8003cc41fa2bb240561b85b9a7f166bc
  • alt-python36-libs-3.6.15-21.el9.x86_64.rpm
    sha:2cb7d604da859fd0d9860c601f0275266d1c22bad11792c9416441f47425a4a1
  • alt-python36-test-3.6.15-21.el9.x86_64.rpm
    sha:c406a81d2ac0f7da513dc6f6e870ff04bd5e06b7da2700477f7cb1509333cc0a
  • alt-python36-tkinter-3.6.15-21.el9.x86_64.rpm
    sha:cdc32cf00d1e68f4b5ed1d0961e1cb0fa6ca1634c2c0f81f530532e95a1c34f1
  • alt-python36-tools-3.6.15-21.el9.x86_64.rpm
    sha:0194dd5434f2a2245350a532de78094fc245090fffe5139562ba6f2365dce840
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.