[CLSA-2026:1787234569] alt-python310: Fix of CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 14:02:59 UTC
Description:
- CVE-2026-6879: cache the indexed sibling lookup in xml.etree.ElementPath predicate selection so Element.findall() and fully-consumed Element.iterfind() with an XPath index predicate no longer call parent.findall() once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings
CVEs fixed:
Updated packages:
  • alt-python310-3.10.20-10.el9.x86_64.rpm
    sha:c7bdcb5f55335d31c39df1bdef90b3eb2713a29e9db3bbc3e58d2f0044079aed
  • alt-python310-debug-3.10.20-10.el9.x86_64.rpm
    sha:edc038fc7a81e812fb0a62ef705767378c96b53d17a0bfa2b14d41c1c99adfcc
  • alt-python310-devel-3.10.20-10.el9.x86_64.rpm
    sha:63aaf7695ad52314aba08d5afc817e45253e002ab6aeb9c26c4320c666a65bcb
  • alt-python310-idle-3.10.20-10.el9.x86_64.rpm
    sha:f619718a01c5f3aea94c27f78718e0b7af51a65e62da71883e0db035bf973958
  • alt-python310-libs-3.10.20-10.el9.x86_64.rpm
    sha:b4de29b8a13c10134b904a9c5d2433485c70d17d16f9936c901c06fa1ef60a1a
  • alt-python310-test-3.10.20-10.el9.x86_64.rpm
    sha:685fb3ee4ea1f2ec0257bd89c2e41e0ccd78f56dfa2d926efd1256b8db8c2a86
  • alt-python310-tkinter-3.10.20-10.el9.x86_64.rpm
    sha:b3cfa97f9c6ca6ca91ad2458ddbd892e134e1cfdfbd86c4a834c06724b096bb8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.