[CLSA-2026:1787230667] Fix CVE(s): CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 12:57:58 UTC
Description:
* SECURITY UPDATE: quadratic complexity in xml.etree XPath index predicates - debian/patches/CVE-2026-6879.patch: cache the indexed sibling lookup in the ElementPath predicate selector so Element.findall() and a fully-consumed Element.iterfind() with an XPath index predicate call parent.findall() once per parent/tag pair instead of once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings - CVE-2026-6879
CVEs fixed:
Updated packages:
  • alt-python310_3.10.20-11_amd64.deb
    sha:5891d3d97a9c16d875615cd29095598d454da4c9
  • alt-python310-debug_3.10.20-11_amd64.deb
    sha:68997f355bde7d993b23c456142c17accab001fd
  • alt-python310-devel_3.10.20-11_amd64.deb
    sha:ac83613bb1480caaf271c9692b12b397469cea19
  • alt-python310-idle_3.10.20-11_amd64.deb
    sha:cc3097c672994ba4977b8073b3f3750f6b54d3c3
  • alt-python310-libs_3.10.20-11_amd64.deb
    sha:03b93b79493bf2744d9c85e97973088a053b22c3
  • alt-python310-test_3.10.20-11_amd64.deb
    sha:e92810769ee0dc3930382d0d69918b33a3f22b33
  • alt-python310-tkinter_3.10.20-11_amd64.deb
    sha:43ff7f8e9a2e2ab4ee8e861016c1470c5862f0bd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.