[CLSA-2026:1787227602] alt-python310: Fix of CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 12:06:52 UTC
Description:
- CVE-2026-6879: cache the indexed sibling lookup in xml.etree.ElementPath predicate selection so Element.findall() and fully-consumed Element.iterfind() with an XPath index predicate no longer call parent.findall() once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings
CVEs fixed:
Updated packages:
  • alt-python310-3.10.20-10.el8.x86_64.rpm
    sha:e22cb318237e4f03d9fa13b2309994731ed45be35545d462f5a9f31dcc1be481
  • alt-python310-debug-3.10.20-10.el8.x86_64.rpm
    sha:527c242f20aef289d38ae6aad4467b4f7d7e33b30449282cea244d098cfafd8b
  • alt-python310-devel-3.10.20-10.el8.x86_64.rpm
    sha:1505a952609b4b20cf97d5d2dceb7687ad90c6bf01599ab302fbab3229fd3f20
  • alt-python310-idle-3.10.20-10.el8.x86_64.rpm
    sha:34cc08abd30f18608146b5bda582fbdb66aded89f934be855746f7757d6c926f
  • alt-python310-libs-3.10.20-10.el8.x86_64.rpm
    sha:cbc860991bf312f4b22080837fe7350d287b06a05c843ab7328c881d02b06120
  • alt-python310-test-3.10.20-10.el8.x86_64.rpm
    sha:274efaad2a40457abea83baf9e42751058d44b36e2b4e632d6378ca358b2e95b
  • alt-python310-tkinter-3.10.20-10.el8.x86_64.rpm
    sha:fed7579ebb40106602c5e72f120f53e1366df9b02c2831d5d5be20184007dc56
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.