Release date:
2026-04-28 15:47:18 UTC
Description:
* SECURITY UPDATE: zipfile quoted-overlap zip bomb
- debian/patches/CVE-2024-0450.patch: raise BadZipFile when an
archive entry overlaps with another entry or the central
directory, preventing quoted-overlap zip bombs with extreme
compression ratios.
- CVE-2024-0450
* SECURITY UPDATE: use-after-free in lzma/bz2 decompressors
- debian/patches/CVE-2026-6100.patch: null next_in at the error:
label of decompress() in Modules/_bz2module.c and
Modules/_lzmamodule.c so the decompressor cannot be re-used
with a stale buffer pointer after a MemoryError.
- CVE-2026-6100
Updated packages:
-
alt-python36_3.6.15-30_amd64.deb
sha:3d298fd731193dd55145c01df16ca71af33d64b6
-
alt-python36-debug_3.6.15-30_amd64.deb
sha:293cbd657712a2d899f9f89f31f1f0badf50c0e4
-
alt-python36-devel_3.6.15-30_amd64.deb
sha:814fdda4cc17efbdb2819ac5dabf8d946c64d271
-
alt-python36-libs_3.6.15-30_amd64.deb
sha:9da60134bd27520d63aa76da9c6570e26d2c8e74
-
alt-python36-test_3.6.15-30_amd64.deb
sha:8b1e90a0ed1af51e1a5b954e68925418509cd5b7
-
alt-python36-tkinter_3.6.15-30_amd64.deb
sha:b0df36551a16e6d6e38b52ae0a7d271a7a6ad1f7
-
alt-python36-tools_3.6.15-30_amd64.deb
sha:e176a6d94a041e876245a9dc84aae5fcb59174be
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.