{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: base64 decoder silently discarded data after the first\n     padded quad\n     - debian/patches/00476-CVE-2026-3446-base64-excess-data-after-padding.patch:\n       backport of cpython 1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474 (gh-145264).\n       In non-strict (default) mode binascii.a2b_base64() stopped at the first\n       padded quad and dropped everything after it instead of ignoring the pad\n       character per RFC 4648 section 3.3, so an attacker could append data our\n       decoder discards but another implementation retains. Backs\n       base64.b64decode(), standard_b64decode() and urlsafe_b64decode().\n     - CVE-2026-3446",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149",
        "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_python/debian13/advisories/2026/clsa-2026_1788186149.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-31T14:23:34Z",
      "generator": {
        "date": "2026-08-31T14:23:34Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788186149",
      "initial_release_date": "2026-08-31T14:23:34Z",
      "revision_history": [
        {
          "date": "2026-08-31T14:23:34Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2025-4517, CVE-2026-3446, CVE-2026-6100"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 13",
                "product": {
                  "name": "Debian 13",
                  "product_id": "Debian-13",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:13:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-python312-idle-0:3.12.14-3.arm64",
                "product": {
                  "name": "alt-python312-idle-0:3.12.14-3.arm64",
                  "product_id": "alt-python312-idle-0:3.12.14-3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-idle@3.12.14-3?arch=arm64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-tkinter-0:3.12.14-3.arm64",
                "product": {
                  "name": "alt-python312-tkinter-0:3.12.14-3.arm64",
                  "product_id": "alt-python312-tkinter-0:3.12.14-3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-tkinter@3.12.14-3?arch=arm64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-test-0:3.12.14-3.arm64",
                "product": {
                  "name": "alt-python312-test-0:3.12.14-3.arm64",
                  "product_id": "alt-python312-test-0:3.12.14-3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-test@3.12.14-3?arch=arm64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-debug-0:3.12.14-3.arm64",
                "product": {
                  "name": "alt-python312-debug-0:3.12.14-3.arm64",
                  "product_id": "alt-python312-debug-0:3.12.14-3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-debug@3.12.14-3?arch=arm64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-libs-0:3.12.14-3.arm64",
                "product": {
                  "name": "alt-python312-libs-0:3.12.14-3.arm64",
                  "product_id": "alt-python312-libs-0:3.12.14-3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-libs@3.12.14-3?arch=arm64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-0:3.12.14-3.arm64",
                "product": {
                  "name": "alt-python312-0:3.12.14-3.arm64",
                  "product_id": "alt-python312-0:3.12.14-3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312@3.12.14-3?arch=arm64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-devel-0:3.12.14-3.arm64",
                "product": {
                  "name": "alt-python312-devel-0:3.12.14-3.arm64",
                  "product_id": "alt-python312-devel-0:3.12.14-3.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-devel@3.12.14-3?arch=arm64&os_name=debian&os_version=13"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-python312-idle-0:3.12.14-3.amd64",
                "product": {
                  "name": "alt-python312-idle-0:3.12.14-3.amd64",
                  "product_id": "alt-python312-idle-0:3.12.14-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-idle@3.12.14-3?arch=amd64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-tkinter-0:3.12.14-3.amd64",
                "product": {
                  "name": "alt-python312-tkinter-0:3.12.14-3.amd64",
                  "product_id": "alt-python312-tkinter-0:3.12.14-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-tkinter@3.12.14-3?arch=amd64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-test-0:3.12.14-3.amd64",
                "product": {
                  "name": "alt-python312-test-0:3.12.14-3.amd64",
                  "product_id": "alt-python312-test-0:3.12.14-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-test@3.12.14-3?arch=amd64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-debug-0:3.12.14-3.amd64",
                "product": {
                  "name": "alt-python312-debug-0:3.12.14-3.amd64",
                  "product_id": "alt-python312-debug-0:3.12.14-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-debug@3.12.14-3?arch=amd64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-libs-0:3.12.14-3.amd64",
                "product": {
                  "name": "alt-python312-libs-0:3.12.14-3.amd64",
                  "product_id": "alt-python312-libs-0:3.12.14-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-libs@3.12.14-3?arch=amd64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-0:3.12.14-3.amd64",
                "product": {
                  "name": "alt-python312-0:3.12.14-3.amd64",
                  "product_id": "alt-python312-0:3.12.14-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312@3.12.14-3?arch=amd64&os_name=debian&os_version=13"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python312-devel-0:3.12.14-3.amd64",
                "product": {
                  "name": "alt-python312-devel-0:3.12.14-3.amd64",
                  "product_id": "alt-python312-devel-0:3.12.14-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python312-devel@3.12.14-3?arch=amd64&os_name=debian&os_version=13"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-idle-0:3.12.14-3.arm64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-idle-0:3.12.14-3.arm64"
        },
        "product_reference": "alt-python312-idle-0:3.12.14-3.arm64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-idle-0:3.12.14-3.amd64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-idle-0:3.12.14-3.amd64"
        },
        "product_reference": "alt-python312-idle-0:3.12.14-3.amd64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-tkinter-0:3.12.14-3.arm64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-tkinter-0:3.12.14-3.arm64"
        },
        "product_reference": "alt-python312-tkinter-0:3.12.14-3.arm64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-tkinter-0:3.12.14-3.amd64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-tkinter-0:3.12.14-3.amd64"
        },
        "product_reference": "alt-python312-tkinter-0:3.12.14-3.amd64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-test-0:3.12.14-3.arm64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-test-0:3.12.14-3.arm64"
        },
        "product_reference": "alt-python312-test-0:3.12.14-3.arm64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-test-0:3.12.14-3.amd64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-test-0:3.12.14-3.amd64"
        },
        "product_reference": "alt-python312-test-0:3.12.14-3.amd64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-debug-0:3.12.14-3.amd64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-debug-0:3.12.14-3.amd64"
        },
        "product_reference": "alt-python312-debug-0:3.12.14-3.amd64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-debug-0:3.12.14-3.arm64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-debug-0:3.12.14-3.arm64"
        },
        "product_reference": "alt-python312-debug-0:3.12.14-3.arm64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-libs-0:3.12.14-3.arm64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-libs-0:3.12.14-3.arm64"
        },
        "product_reference": "alt-python312-libs-0:3.12.14-3.arm64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-libs-0:3.12.14-3.amd64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-libs-0:3.12.14-3.amd64"
        },
        "product_reference": "alt-python312-libs-0:3.12.14-3.amd64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-0:3.12.14-3.arm64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-0:3.12.14-3.arm64"
        },
        "product_reference": "alt-python312-0:3.12.14-3.arm64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-0:3.12.14-3.amd64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-0:3.12.14-3.amd64"
        },
        "product_reference": "alt-python312-0:3.12.14-3.amd64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-devel-0:3.12.14-3.amd64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-devel-0:3.12.14-3.amd64"
        },
        "product_reference": "alt-python312-devel-0:3.12.14-3.amd64",
        "relates_to_product_reference": "Debian-13"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python312-devel-0:3.12.14-3.arm64 as a component of Debian 13",
          "product_id": "Debian-13:alt-python312-devel-0:3.12.14-3.arm64"
        },
        "product_reference": "alt-python312-devel-0:3.12.14-3.arm64",
        "relates_to_product_reference": "Debian-13"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-6100",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.\n\nThe vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-13:alt-python312-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-debug-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-debug-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-devel-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-devel-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-idle-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-idle-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-libs-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-libs-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-test-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-test-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-tkinter-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-tkinter-0:3.12.14-3.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e",
          "url": "https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d",
          "url": "https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2",
          "url": "https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20",
          "url": "https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b",
          "url": "https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3",
          "url": "https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/issues/148395",
          "url": "https://github.com/python/cpython/issues/148395"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/148396",
          "url": "https://github.com/python/cpython/pull/148396"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/13/10",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/13/10"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10117",
          "url": "https://access.redhat.com/errata/RHSA-2026:10117"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10140",
          "url": "https://access.redhat.com/errata/RHSA-2026:10140"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10141",
          "url": "https://access.redhat.com/errata/RHSA-2026:10141"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10711",
          "url": "https://access.redhat.com/errata/RHSA-2026:10711"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10745",
          "url": "https://access.redhat.com/errata/RHSA-2026:10745"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10774",
          "url": "https://access.redhat.com/errata/RHSA-2026:10774"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10949",
          "url": "https://access.redhat.com/errata/RHSA-2026:10949"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10950",
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11062",
          "url": "https://access.redhat.com/errata/RHSA-2026:11062"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11077",
          "url": "https://access.redhat.com/errata/RHSA-2026:11077"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11768",
          "url": "https://access.redhat.com/errata/RHSA-2026:11768"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13692",
          "url": "https://access.redhat.com/errata/RHSA-2026:13692"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13812",
          "url": "https://access.redhat.com/errata/RHSA-2026:13812"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14652",
          "url": "https://access.redhat.com/errata/RHSA-2026:14652"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14653",
          "url": "https://access.redhat.com/errata/RHSA-2026:14653"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14656",
          "url": "https://access.redhat.com/errata/RHSA-2026:14656"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16699",
          "url": "https://access.redhat.com/errata/RHSA-2026:16699"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17525",
          "url": "https://access.redhat.com/errata/RHSA-2026:17525"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17619",
          "url": "https://access.redhat.com/errata/RHSA-2026:17619"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19019",
          "url": "https://access.redhat.com/errata/RHSA-2026:19019"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19064",
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19175",
          "url": "https://access.redhat.com/errata/RHSA-2026:19175"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19176",
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19177",
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19216",
          "url": "https://access.redhat.com/errata/RHSA-2026:19216"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19549",
          "url": "https://access.redhat.com/errata/RHSA-2026:19549"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19570",
          "url": "https://access.redhat.com/errata/RHSA-2026:19570"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19571",
          "url": "https://access.redhat.com/errata/RHSA-2026:19571"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19576",
          "url": "https://access.redhat.com/errata/RHSA-2026:19576"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19590",
          "url": "https://access.redhat.com/errata/RHSA-2026:19590"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21275",
          "url": "https://access.redhat.com/errata/RHSA-2026:21275"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21682",
          "url": "https://access.redhat.com/errata/RHSA-2026:21682"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:25096",
          "url": "https://access.redhat.com/errata/RHSA-2026:25096"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:26187",
          "url": "https://access.redhat.com/errata/RHSA-2026:26187"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30078",
          "url": "https://access.redhat.com/errata/RHSA-2026:30078"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30087",
          "url": "https://access.redhat.com/errata/RHSA-2026:30087"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30088",
          "url": "https://access.redhat.com/errata/RHSA-2026:30088"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30089",
          "url": "https://access.redhat.com/errata/RHSA-2026:30089"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:52400",
          "url": "https://access.redhat.com/errata/RHSA-2026:52400"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8822",
          "url": "https://access.redhat.com/errata/RHSA-2026:8822"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8824",
          "url": "https://access.redhat.com/errata/RHSA-2026:8824"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9228",
          "url": "https://access.redhat.com/errata/RHSA-2026:9228"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-6100",
          "url": "https://access.redhat.com/security/cve/CVE-2026-6100"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json"
        }
      ],
      "release_date": "2026-04-13T18:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T14:22:32.003457Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149",
          "product_ids": [
            "Debian-13:alt-python312-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-debug-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-debug-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-devel-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-devel-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-idle-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-idle-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-libs-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-libs-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-test-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-test-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-tkinter-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-tkinter-0:3.12.14-3.arm64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-3446",
      "cwe": {
        "id": "CWE-345",
        "name": "Insufficient Verification of Data Authenticity"
      },
      "notes": [
        {
          "category": "description",
          "text": "When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-13:alt-python312-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-debug-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-debug-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-devel-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-devel-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-idle-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-idle-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-libs-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-libs-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-test-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-test-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-tkinter-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-tkinter-0:3.12.14-3.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474",
          "url": "https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e",
          "url": "https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa",
          "url": "https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/issues/145264",
          "url": "https://github.com/python/cpython/issues/145264"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/145267",
          "url": "https://github.com/python/cpython/pull/145267"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"
        }
      ],
      "release_date": "2026-04-10T19:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T14:22:32.003457Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149",
          "product_ids": [
            "Debian-13:alt-python312-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-debug-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-debug-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-devel-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-devel-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-idle-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-idle-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-libs-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-libs-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-test-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-test-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-tkinter-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-tkinter-0:3.12.14-3.arm64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-4517",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-13:alt-python312-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-debug-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-debug-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-devel-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-devel-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-idle-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-idle-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-libs-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-libs-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-test-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-test-0:3.12.14-3.arm64",
          "Debian-13:alt-python312-tkinter-0:3.12.14-3.amd64",
          "Debian-13:alt-python312-tkinter-0:3.12.14-3.arm64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517"
        },
        {
          "category": "external",
          "summary": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f",
          "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da",
          "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9",
          "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a",
          "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e",
          "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a",
          "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a",
          "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01",
          "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1",
          "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/issues/135034",
          "url": "https://github.com/python/cpython/issues/135034"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/135037",
          "url": "https://github.com/python/cpython/pull/135037"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"
        }
      ],
      "release_date": "2025-06-03T13:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-31T14:22:32.003457Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149",
          "product_ids": [
            "Debian-13:alt-python312-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-debug-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-debug-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-devel-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-devel-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-idle-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-idle-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-libs-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-libs-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-test-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-test-0:3.12.14-3.arm64",
            "Debian-13:alt-python312-tkinter-0:3.12.14-3.amd64",
            "Debian-13:alt-python312-tkinter-0:3.12.14-3.arm64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1788186149"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}