[CLSA-2026:1787223801] alt-python310: Fix of CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 11:03:31 UTC
Description:
- CVE-2026-6879: cache the indexed sibling lookup in xml.etree.ElementPath predicate selection so Element.findall() and fully-consumed Element.iterfind() with an XPath index predicate no longer call parent.findall() once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings
CVEs fixed:
Updated packages:
  • alt-python310-3.10.20-10.el7.x86_64.rpm
    sha:67d0797498fb169da226e5d44d07e07b1391961f7365258d9edc4b4f345f2510
  • alt-python310-debug-3.10.20-10.el7.x86_64.rpm
    sha:36bc53c2e94c11b50e3c48d4f9a33b509de394ed267d1e802042e2ffab9385ef
  • alt-python310-devel-3.10.20-10.el7.x86_64.rpm
    sha:96e85f865a7f7f0a3cc2b72720f805594a1f466514cc7e695edcf13e6010c9ab
  • alt-python310-idle-3.10.20-10.el7.x86_64.rpm
    sha:f5328caa29bff53a532648b689c75e9cc6d9abc249acff61728ef454c15cedc9
  • alt-python310-libs-3.10.20-10.el7.x86_64.rpm
    sha:6478bd4cb161da3d3952cddcbb8dcaba23bbb87a5fe1e14e2e3fde198f609817
  • alt-python310-test-3.10.20-10.el7.x86_64.rpm
    sha:4ef0c051e58f32b7853647910833a2817a2a0ecdf8db300e2741389a6db02895
  • alt-python310-tkinter-3.10.20-10.el7.x86_64.rpm
    sha:175d47102667de32ec7427ddb1521f9646b4d17502e8f8d48f40c2feb2d9c7ed
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.