Release date:
2026-05-13 14:17:12 UTC
Description:
* SECURITY UPDATE: binascii.a2b_base64 / base64.b64decode stop decoding
after the first padded quad, silently dropping any excess data. The
behaviour can lead to data being accepted that other implementations
process differently.
- debian/patches/CVE-2026-3446.patch: backport of upstream commits
4561f6418a (main), e31c55121620 (3.14), 1f9958f909c1 (3.13). Treats
the pad character as non-alphabet data per RFC 4648 section 3.3:
the loop in binascii_a2b_base64_impl no longer breaks out on a pad
sequence; a `pads` counter is added so post-loop validation still
raises "Incorrect padding" for inputs that do not satisfy
`quad_pos + pads == 4`. The unused `binascii_find_valid` helper
is removed.
- CVE-2026-3446
Updated packages:
-
alt-python36_3.6.15-32_amd64.deb
sha:dd9ebabf04bde8a40a00e9b049fde247b235112d
-
alt-python36-debug_3.6.15-32_amd64.deb
sha:a67042dd6de5d0f105382fb87a922bce4ac98cb7
-
alt-python36-devel_3.6.15-32_amd64.deb
sha:efb4aa2c1a982735f95bc7bd4bf9f9ea4ee445b1
-
alt-python36-libs_3.6.15-32_amd64.deb
sha:e841c0dad40d1d588002cab864efc5b26d695db9
-
alt-python36-test_3.6.15-32_amd64.deb
sha:4a92c5c1e6b851d3a0ef6f0bb459654725ed7bf8
-
alt-python36-tkinter_3.6.15-32_amd64.deb
sha:0a4a9f7f2182b28c8f1ac08ba0c4b23636e9c609
-
alt-python36-tools_3.6.15-32_amd64.deb
sha:3dbb45a7e8d5bb546c43c6972099dbe768092ba2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.