Release date:
2026-08-20 10:37:17 UTC
Description:
- CVE-2026-4360: apply the selected extraction filter when tarfile.TarFile.extract() falls back to extracting a hardlink target, instead of extracting it unfiltered (extraction filter bypass)
- CVE-2026-6879: fix quadratic complexity in xml.etree XPath index predicates by memoising the indexed match per parent and tag (CPU denial-of-service)
Updated packages:
-
alt-python311-3.11.15-7.el10.x86_64.rpm
sha:b11e53524fd5f396a5d65e5a1e20aca58c93209e35a3fb2da37e9e9f42cbaf52
-
alt-python311-debug-3.11.15-7.el10.x86_64.rpm
sha:53757e6727233778d4b5225e29a203ea305d7a997cc524926fdb10ebc9285b75
-
alt-python311-devel-3.11.15-7.el10.x86_64.rpm
sha:3bfed37bb5dd3d74ada958cb761ef3e71f9e9b9772d6446e6365acda6ba5b804
-
alt-python311-idle-3.11.15-7.el10.x86_64.rpm
sha:d0729edcc14921ae4a7de3faca1ba3b18d4deeac000eb202abadab8de3c68003
-
alt-python311-libs-3.11.15-7.el10.x86_64.rpm
sha:87d6e7e5ce5e8b1f758b045f76ac68d4ba1e0529fb5c8e1b342165008c30814a
-
alt-python311-test-3.11.15-7.el10.x86_64.rpm
sha:1cc5bb014abb34b4d11fbde42f0149d5ce4cb8047125cf52dd5ade33805dca2e
-
alt-python311-tkinter-3.11.15-7.el10.x86_64.rpm
sha:f09981cf12939556f95062e5c4691ea3304b083c0343884a289fa9d3bd811831
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.