[CLSA-2026:1788181663] Fix CVE(s): CVE-2025-4517, CVE-2026-3446, CVE-2026-6100
Type:
security
Severity:
Critical
Release date:
2026-08-31 13:07:57 UTC
Description:
* SECURITY UPDATE: base64 decoder silently discarded data after the first padded quad - debian/patches/00476-CVE-2026-3446-base64-excess-data-after-padding.patch: backport of cpython 1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474 (gh-145264). In non-strict (default) mode binascii.a2b_base64() stopped at the first padded quad and dropped everything after it instead of ignoring the pad character per RFC 4648 section 3.3, so an attacker could append data our decoder discards but another implementation retains. Backs base64.b64decode(), standard_b64decode() and urlsafe_b64decode(). - CVE-2026-3446
Updated packages:
  • alt-python312_3.12.14-3_amd64.deb
    sha:1822858e5fae20d077a4860d2d09cdbb4bc0004a
  • alt-python312-debug_3.12.14-3_amd64.deb
    sha:0465182ad470f783d3ba1f1499ff08f22c77674e
  • alt-python312-devel_3.12.14-3_amd64.deb
    sha:71d08cf703651514d6eecde078a8a8afc5940090
  • alt-python312-idle_3.12.14-3_amd64.deb
    sha:7e11eab8a2991bdd48ba2c98fe19a13e7f591018
  • alt-python312-libs_3.12.14-3_amd64.deb
    sha:3939dfe4218842d8764d224ce77cafade34746f1
  • alt-python312-test_3.12.14-3_amd64.deb
    sha:a2d807d2061f82548bdc9f8e3e60b140b81e594f
  • alt-python312-tkinter_3.12.14-3_amd64.deb
    sha:3678d5a35367b8fd3bb511006c5b760beb634cef
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.