Release date:
2026-08-20 08:15:11 UTC
Description:
- CVE-2026-4360: apply the selected extraction filter when tarfile.TarFile.extract() falls back to extracting a hardlink target, instead of extracting it unfiltered (extraction filter bypass)
- CVE-2026-6879: fix quadratic complexity in xml.etree XPath index predicates by memoising the indexed match per parent and tag (CPU denial-of-service)
Updated packages:
-
alt-python311-3.11.15-7.el7.x86_64.rpm
sha:fd5eb4af892f7a106630ff07795a8108b23aa3ded9c755028e2404e3d6705c3d
-
alt-python311-debug-3.11.15-7.el7.x86_64.rpm
sha:106b8206595c862923480709642b739f1009ff1b26c6bc2c7ba2c5efd3d33dd3
-
alt-python311-devel-3.11.15-7.el7.x86_64.rpm
sha:1cb39fac65038a24f1301a9b527e0c7593a6b5a901b84157c57c5f9b76b48f97
-
alt-python311-idle-3.11.15-7.el7.x86_64.rpm
sha:2486d5b1e2c4e7c1969f34527cf508925a51c570d29d8cb3c58bb09ef8fea801
-
alt-python311-libs-3.11.15-7.el7.x86_64.rpm
sha:2a394648ad0bc5c6ec44e2bb61cef6aed59ce0a59ef88b342cf6928cc3180081
-
alt-python311-test-3.11.15-7.el7.x86_64.rpm
sha:cbd8a0373d1ad6ceea493a3bce28dff7c840ed5125f88810727e3d7d1d8ca16b
-
alt-python311-tkinter-3.11.15-7.el7.x86_64.rpm
sha:3fc49fd3f5904837ccda4a6eaecf0472d032148c250405dbcf5257aeaf0b1132
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.