Release date:
2026-04-28 15:38:35 UTC
Description:
* SECURITY UPDATE: zipfile quoted-overlap zip bomb
- debian/patches/CVE-2024-0450.patch: raise BadZipFile when an
archive entry overlaps with another entry or the central
directory, preventing quoted-overlap zip bombs with extreme
compression ratios.
- CVE-2024-0450
* SECURITY UPDATE: use-after-free in lzma/bz2 decompressors
- debian/patches/CVE-2026-6100.patch: null next_in at the error:
label of decompress() in Modules/_bz2module.c and
Modules/_lzmamodule.c so the decompressor cannot be re-used
with a stale buffer pointer after a MemoryError.
- CVE-2026-6100
Updated packages:
-
alt-python36_3.6.15-30_amd64.deb
sha:fd01da8a0f7836388a996b70a20532aecac1a588
-
alt-python36-debug_3.6.15-30_amd64.deb
sha:c96e36aaabc4517e4e4c97d15ccf3795b9982042
-
alt-python36-devel_3.6.15-30_amd64.deb
sha:9f52e32eea261994e7f8a7b833f190362677a139
-
alt-python36-libs_3.6.15-30_amd64.deb
sha:fc6cee51a8464db4ae80c9b42f6aaa1ca3c3bf35
-
alt-python36-test_3.6.15-30_amd64.deb
sha:c7e5a26d32a56803c46fecc330b721fe96a38a16
-
alt-python36-tkinter_3.6.15-30_amd64.deb
sha:1468deeb0d0981e14fa58f708c1f786b522a0b62
-
alt-python36-tools_3.6.15-30_amd64.deb
sha:d2fb927a26b638b449156122f2de0f275cd93239
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.