[CLSA-2026:1787222226] alt-python311: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-20 10:37:17 UTC
Description:
- CVE-2026-4360: apply the selected extraction filter when tarfile.TarFile.extract() falls back to extracting a hardlink target, instead of extracting it unfiltered (extraction filter bypass) - CVE-2026-6879: fix quadratic complexity in xml.etree XPath index predicates by memoising the indexed match per parent and tag (CPU denial-of-service)
Updated packages:
  • alt-python311-3.11.15-7.el10.x86_64.rpm
    sha:b11e53524fd5f396a5d65e5a1e20aca58c93209e35a3fb2da37e9e9f42cbaf52
  • alt-python311-debug-3.11.15-7.el10.x86_64.rpm
    sha:53757e6727233778d4b5225e29a203ea305d7a997cc524926fdb10ebc9285b75
  • alt-python311-devel-3.11.15-7.el10.x86_64.rpm
    sha:3bfed37bb5dd3d74ada958cb761ef3e71f9e9b9772d6446e6365acda6ba5b804
  • alt-python311-idle-3.11.15-7.el10.x86_64.rpm
    sha:d0729edcc14921ae4a7de3faca1ba3b18d4deeac000eb202abadab8de3c68003
  • alt-python311-libs-3.11.15-7.el10.x86_64.rpm
    sha:87d6e7e5ce5e8b1f758b045f76ac68d4ba1e0529fb5c8e1b342165008c30814a
  • alt-python311-test-3.11.15-7.el10.x86_64.rpm
    sha:1cc5bb014abb34b4d11fbde42f0149d5ce4cb8047125cf52dd5ade33805dca2e
  • alt-python311-tkinter-3.11.15-7.el10.x86_64.rpm
    sha:f09981cf12939556f95062e5c4691ea3304b083c0343884a289fa9d3bd811831
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.