[CLSA-2026:1788184963] Fix CVE(s): CVE-2025-4517, CVE-2026-3446, CVE-2026-6100
Type:
security
Severity:
Critical
Release date:
2026-08-31 14:02:57 UTC
Description:
* SECURITY UPDATE: base64 decoder silently discarded data after the first padded quad - debian/patches/00476-CVE-2026-3446-base64-excess-data-after-padding.patch: backport of cpython 1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474 (gh-145264). In non-strict (default) mode binascii.a2b_base64() stopped at the first padded quad and dropped everything after it instead of ignoring the pad character per RFC 4648 section 3.3, so an attacker could append data our decoder discards but another implementation retains. Backs base64.b64decode(), standard_b64decode() and urlsafe_b64decode(). - CVE-2026-3446
Updated packages:
  • alt-python312_3.12.14-3_amd64.deb
    sha:04b41ad612317f58405c545964576f77b856ae13
  • alt-python312-debug_3.12.14-3_amd64.deb
    sha:a3f154ab139043e8e6b7abdb6c39561483ba7480
  • alt-python312-devel_3.12.14-3_amd64.deb
    sha:39813984645866d646ca57e284640a9722f9d971
  • alt-python312-idle_3.12.14-3_amd64.deb
    sha:f8ebb52ee41aa13affa1c0549c61406897c95d59
  • alt-python312-libs_3.12.14-3_amd64.deb
    sha:9e968dfc1a0da4cb68f1543c66d9ac0548d29bca
  • alt-python312-test_3.12.14-3_amd64.deb
    sha:60d35d9f8662cf8ecf51e06559452a3121b64224
  • alt-python312-tkinter_3.12.14-3_amd64.deb
    sha:7ba857b7db890b8a6620914c00cc2af21900831e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.