Release date:
2026-08-20 08:47:26 UTC
Description:
- CVE-2026-4360: apply the selected extraction filter when tarfile.TarFile.extract() falls back to extracting a hardlink target, instead of extracting it unfiltered (extraction filter bypass)
- CVE-2026-6879: fix quadratic complexity in xml.etree XPath index predicates by memoising the indexed match per parent and tag (CPU denial-of-service)
Updated packages:
-
alt-python311-3.11.15-7.el9.x86_64.rpm
sha:f90cc2e514e898cacf2468a344174398bea8e80267393b3afcd805ddc8e260a6
-
alt-python311-debug-3.11.15-7.el9.x86_64.rpm
sha:1531b65d684623ad7daa7c4e00191f2658b392b469f060bc27e5c1b138faa662
-
alt-python311-devel-3.11.15-7.el9.x86_64.rpm
sha:94f99c139666244ca867bee660390b4a3dbd8c8f57143677043a3ee76358edaa
-
alt-python311-idle-3.11.15-7.el9.x86_64.rpm
sha:808c9b19566fcf4a11ede0e11d8a55b245a67e6ddf643394bdbec0ca2cdfcd73
-
alt-python311-libs-3.11.15-7.el9.x86_64.rpm
sha:b69463c535a3d6f74f96456fb7778908477263acd08c067d8db4df9119fdbdb6
-
alt-python311-test-3.11.15-7.el9.x86_64.rpm
sha:0b47d83654a3f874989fcab077034a55bf98acb81c3c30160d1d84ce9140fb09
-
alt-python311-tkinter-3.11.15-7.el9.x86_64.rpm
sha:f244c4d4b5c185174c46ad416ed643acea60478af706d7f7f3cd50e348043da1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.