[CLSA-2026:1772210148] Fix CVE(s): CVE-2025-6075
Type:
security
Severity:
Moderate
Release date:
2026-02-27 16:35:53 UTC
Description:
* SECURITY UPDATE: Quadratic complexity in os.path.expandvars() - debian/patches/CVE-2025-6075.patch: fix quadratic complexity in os.path.expandvars() by replacing the character-by-character loop with regex-based substitution in both posixpath and ntpath modules. - CVE-2025-6075
Updated packages:
  • alt-python39_3.9.23-8_amd64.deb
    sha:12494c7ce5db18bcb5a8db94c36678dfdebc85cc
  • alt-python39-debug_3.9.23-8_amd64.deb
    sha:f92d0e86b387b9fac43dc824ed869d44256a2175
  • alt-python39-devel_3.9.23-8_amd64.deb
    sha:37b982fce2006506fab935461159d27508eb7740
  • alt-python39-idle_3.9.23-8_amd64.deb
    sha:75a9cd440f13385f920bb95e3eebd3513960d783
  • alt-python39-libs_3.9.23-8_amd64.deb
    sha:8abfb70e38e177d5b199d60991847435137ed589
  • alt-python39-test_3.9.23-8_amd64.deb
    sha:7679abb056659bdd817e167a1b2566f2352edd9b
  • alt-python39-tkinter_3.9.23-8_amd64.deb
    sha:4414f7e5e9146ec4df89c08338f60a6189537db2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.