[CLSA-2026:1772620885] Fix CVE(s): CVE-2025-6075
Type:
security
Severity:
Moderate
Release date:
2026-03-04 10:41:30 UTC
Description:
* SECURITY UPDATE: Quadratic complexity in os.path.expandvars() - debian/patches/CVE-2025-6075.patch: fix quadratic complexity in os.path.expandvars() by replacing the character-by-character loop with regex-based substitution in both posixpath and ntpath modules. - CVE-2025-6075
Updated packages:
  • alt-python38_3.8.20-10_amd64.deb
    sha:9e42f854ca048809584cc1fbb02afbf16f470489
  • alt-python38-debug_3.8.20-10_amd64.deb
    sha:9fbea63578a2a41f4abf751c41483e82c626e58b
  • alt-python38-devel_3.8.20-10_amd64.deb
    sha:3c31a59e8a7fa1cb65ddeeb63f195cfd553aa4bd
  • alt-python38-idle_3.8.20-10_amd64.deb
    sha:0d26da1298a0daa30036c92c3fb398c09825a19a
  • alt-python38-libs_3.8.20-10_amd64.deb
    sha:8e1fc47e17e9bd8aea2db500a521893783601279
  • alt-python38-test_3.8.20-10_amd64.deb
    sha:1502b98b077ca8069476bbc7264ce7c01da325b6
  • alt-python38-tkinter_3.8.20-10_amd64.deb
    sha:fd526d71f6f24d37bdca5ecd23c36b8aa3bb705f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.