Release Info

Advisory: CLSA-2026:1768588081

OS: Debian 13

Public date: 2026-01-16 18:28:03.220854

Project: python

Version: 3.8.20-5

Errata link: https://errata.tuxcare.com/els_alt_python/debian13/CLSA-2026-1768588081.html

Changelog

* SECURITY UPDATE: Potential denial of service in http.client - debian/patches/CVE-2025-13836.patch: Read large data by chunks instead of allocating memory based on Content-Length - CVE-2025-13836 * SECURITY UPDATE: Quadratic complexity in xml.minidom node ID cache clearing - debian/patches/CVE-2025-12084.patch: Remove quadratic behavior in xml.minidom node ID cache clearing - CVE-2025-12084

Update

Update command: apt-get update apt-get --only-upgrade install alt-python*

Packages list

alt-python38_3.8.20-5_amd64.deb alt-python38-debug_3.8.20-5_amd64.deb alt-python38-devel_3.8.20-5_amd64.deb alt-python38-idle_3.8.20-5_amd64.deb alt-python38-libs_3.8.20-5_amd64.deb alt-python38-test_3.8.20-5_amd64.deb alt-python38-tkinter_3.8.20-5_amd64.deb

CVEs

CVE-2025-12084
CVE-2025-13836