Release date:
2026-08-20 08:39:59 UTC
Description:
- CVE-2026-4360: apply the selected extraction filter when tarfile.TarFile.extract() falls back to extracting a hardlink target, instead of extracting it unfiltered (extraction filter bypass)
- CVE-2026-6879: fix quadratic complexity in xml.etree XPath index predicates by memoising the indexed match per parent and tag (CPU denial-of-service)
Updated packages:
-
alt-python311-3.11.15-7.el8.x86_64.rpm
sha:0667313fa62cdb4fafd148c1e393c94a3199581fd0151157237ff63a3da4098b
-
alt-python311-debug-3.11.15-7.el8.x86_64.rpm
sha:1ae616136603a3e179955c7899a37d9026bc201fae18c4834163d2e2066188a3
-
alt-python311-devel-3.11.15-7.el8.x86_64.rpm
sha:05ead4f2de7079319fe72c986451a7ab97c0c12c1f99ee510e56cd24dcbd4564
-
alt-python311-idle-3.11.15-7.el8.x86_64.rpm
sha:d04194c1e52457cea588353687490a1fa57374ae610e157175c94d13954dc8f8
-
alt-python311-libs-3.11.15-7.el8.x86_64.rpm
sha:54d6032d663636216e9d71b81ae8099cb4751061f77732fb3f1fb26442baf1a3
-
alt-python311-test-3.11.15-7.el8.x86_64.rpm
sha:600add1a627fd554b7f358aa75525e569c526c5c68793f06c2e496b474c593f7
-
alt-python311-tkinter-3.11.15-7.el8.x86_64.rpm
sha:3e0a8b127e14a851b62034765dbf03b34c699548e578ceb3596d1dfa2e5666c0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.