[CLSA-2026:1787224761] Fix CVE(s): CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 11:19:32 UTC
Description:
* SECURITY UPDATE: quadratic complexity in xml.etree XPath index predicates - debian/patches/CVE-2026-6879.patch: cache the indexed sibling lookup in the ElementPath predicate selector so Element.findall() and a fully-consumed Element.iterfind() with an XPath index predicate call parent.findall() once per parent/tag pair instead of once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings - CVE-2026-6879
CVEs fixed:
Updated packages:
  • alt-python310_3.10.20-11_amd64.deb
    sha:2761fe8cd8faa0c448845691d11062cbeb40bf2f
  • alt-python310-debug_3.10.20-11_amd64.deb
    sha:485527d1c04b22ec06b3bbfc22a9b18af7eb55dd
  • alt-python310-devel_3.10.20-11_amd64.deb
    sha:527a0c6592068ba7b03a95a2a20d76dd5b2ea1dd
  • alt-python310-idle_3.10.20-11_amd64.deb
    sha:3d7132ee43dda9c32b65a64345c6050cd86664a2
  • alt-python310-libs_3.10.20-11_amd64.deb
    sha:30bdf40fbd9971d75a548e2d72f410f0464d611f
  • alt-python310-test_3.10.20-11_amd64.deb
    sha:4983703bbc7cc78e7ed41b73325e59c02cc3527d
  • alt-python310-tkinter_3.10.20-11_amd64.deb
    sha:012419842ccce022bbdbedc5a54db438adec95c8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.