[CLSA-2026:1787213698] alt-python311: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-20 08:15:11 UTC
Description:
- CVE-2026-4360: apply the selected extraction filter when tarfile.TarFile.extract() falls back to extracting a hardlink target, instead of extracting it unfiltered (extraction filter bypass) - CVE-2026-6879: fix quadratic complexity in xml.etree XPath index predicates by memoising the indexed match per parent and tag (CPU denial-of-service)
Updated packages:
  • alt-python311-3.11.15-7.el7.x86_64.rpm
    sha:fd5eb4af892f7a106630ff07795a8108b23aa3ded9c755028e2404e3d6705c3d
  • alt-python311-debug-3.11.15-7.el7.x86_64.rpm
    sha:106b8206595c862923480709642b739f1009ff1b26c6bc2c7ba2c5efd3d33dd3
  • alt-python311-devel-3.11.15-7.el7.x86_64.rpm
    sha:1cb39fac65038a24f1301a9b527e0c7593a6b5a901b84157c57c5f9b76b48f97
  • alt-python311-idle-3.11.15-7.el7.x86_64.rpm
    sha:2486d5b1e2c4e7c1969f34527cf508925a51c570d29d8cb3c58bb09ef8fea801
  • alt-python311-libs-3.11.15-7.el7.x86_64.rpm
    sha:2a394648ad0bc5c6ec44e2bb61cef6aed59ce0a59ef88b342cf6928cc3180081
  • alt-python311-test-3.11.15-7.el7.x86_64.rpm
    sha:cbd8a0373d1ad6ceea493a3bce28dff7c840ed5125f88810727e3d7d1d8ca16b
  • alt-python311-tkinter-3.11.15-7.el7.x86_64.rpm
    sha:3fc49fd3f5904837ccda4a6eaecf0472d032148c250405dbcf5257aeaf0b1132
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.