[CLSA-2026:1787238753] Fix CVE(s): CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 15:12:45 UTC
Description:
* SECURITY UPDATE: quadratic complexity in xml.etree XPath index predicates - debian/patches/CVE-2026-6879.patch: cache the indexed sibling lookup in the ElementPath predicate selector so Element.findall() and a fully-consumed Element.iterfind() with an XPath index predicate call parent.findall() once per parent/tag pair instead of once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings - CVE-2026-6879
CVEs fixed:
Updated packages:
  • alt-python310_3.10.20-11_amd64.deb
    sha:07fa31a40531addd0bc5e5010827c8066b9d43b8
  • alt-python310-debug_3.10.20-11_amd64.deb
    sha:176387fd5eca1e2467600b4492ba04fca3f1c3f6
  • alt-python310-devel_3.10.20-11_amd64.deb
    sha:5d2e2bb4449f181f93973fadcd8affe29a07d4e4
  • alt-python310-idle_3.10.20-11_amd64.deb
    sha:ee3c9f534fe0c87f0de8155328f17493fecbdc66
  • alt-python310-libs_3.10.20-11_amd64.deb
    sha:7d1eb3c28666fbc7dfd5e3ea11052ae1f2e2f92b
  • alt-python310-test_3.10.20-11_amd64.deb
    sha:08539842141cf750cca3a9a694c935dc76b29e63
  • alt-python310-tkinter_3.10.20-11_amd64.deb
    sha:eff7fa2fcea7ddf6c7de23e75dd855ce0cb2abc4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.