Release date:
2026-04-28 15:51:18 UTC
Description:
* SECURITY UPDATE: zipfile quoted-overlap zip bomb
- debian/patches/CVE-2024-0450.patch: raise BadZipFile when an
archive entry overlaps with another entry or the central
directory, preventing quoted-overlap zip bombs with extreme
compression ratios.
- CVE-2024-0450
* SECURITY UPDATE: use-after-free in lzma/bz2 decompressors
- debian/patches/CVE-2026-6100.patch: null next_in at the error:
label of decompress() in Modules/_bz2module.c and
Modules/_lzmamodule.c so the decompressor cannot be re-used
with a stale buffer pointer after a MemoryError.
- CVE-2026-6100
Updated packages:
-
alt-python36_3.6.15-30_amd64.deb
sha:b9a5d2a43af66e458cf0b16511df9b6b015bcd48
-
alt-python36-debug_3.6.15-30_amd64.deb
sha:c0925d0e9e5512d7df3a960cda8fb299378012b4
-
alt-python36-devel_3.6.15-30_amd64.deb
sha:b75b30f10032ecb90e94f7c43cbc3e2472175fdb
-
alt-python36-libs_3.6.15-30_amd64.deb
sha:947b06804275596cd4ce20e4ceb96f93f32e935f
-
alt-python36-test_3.6.15-30_amd64.deb
sha:73eaeefecfe9f46c86956a5356abf1470f083908
-
alt-python36-tkinter_3.6.15-30_amd64.deb
sha:3328d85ae089031fdf29102bdae256850bc84919
-
alt-python36-tools_3.6.15-30_amd64.deb
sha:fdb8b83b3470283ee0fc67576547f3cd7068e73f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.