[CLSA-2026:1787232002] alt-python310: Fix of CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 13:20:12 UTC
Description:
- CVE-2026-6879: cache the indexed sibling lookup in xml.etree.ElementPath predicate selection so Element.findall() and fully-consumed Element.iterfind() with an XPath index predicate no longer call parent.findall() once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings
CVEs fixed:
Updated packages:
  • alt-python310-3.10.20-10.el10.x86_64.rpm
    sha:a1ecc7ac24ce23aa019bc183d93ab7dde80a08482f039eb8a9165c4acdc74303
  • alt-python310-debug-3.10.20-10.el10.x86_64.rpm
    sha:cf972bea1ee51e562c18cdc9a5a96693a9704fb8f65f41c8eaec9076c3db376b
  • alt-python310-devel-3.10.20-10.el10.x86_64.rpm
    sha:33d1240c013605b4cbe21de49f84b7e2f425a27900f8d6465d41e4e1d37472e8
  • alt-python310-idle-3.10.20-10.el10.x86_64.rpm
    sha:f2653d1627b0744ae67860b287adff3d0328911a28c0d0600d36a55903fb7a91
  • alt-python310-libs-3.10.20-10.el10.x86_64.rpm
    sha:c0e5da19e1f7308f629eafe6424b19c496ce8fa57784f888964be61d757a41af
  • alt-python310-test-3.10.20-10.el10.x86_64.rpm
    sha:b100f22aaf98c780f02e9b5e27295dffea9482146231426198cc4418a783978e
  • alt-python310-tkinter-3.10.20-10.el10.x86_64.rpm
    sha:e6e4621650f4f625f794678d665160d1fcfa3beb0116b720bebc1ac9d6e08667
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.