[CLSA-2026:1787227798] Fix CVE(s): CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 12:10:09 UTC
Description:
* SECURITY UPDATE: quadratic complexity in xml.etree XPath index predicates - debian/patches/CVE-2026-6879.patch: cache the indexed sibling lookup in the ElementPath predicate selector so Element.findall() and a fully-consumed Element.iterfind() with an XPath index predicate call parent.findall() once per parent/tag pair instead of once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings - CVE-2026-6879
CVEs fixed:
Updated packages:
  • alt-python310_3.10.20-11_amd64.deb
    sha:a1fb5d710122284548d9d1c678f9c0c5002c8710
  • alt-python310-debug_3.10.20-11_amd64.deb
    sha:a0af5724e16b97e3dfd36f3c1dc8db3b4f0fc5f9
  • alt-python310-devel_3.10.20-11_amd64.deb
    sha:54b37944a5ab761819027faeabdee1aa9caefc18
  • alt-python310-idle_3.10.20-11_amd64.deb
    sha:18d5a46caedd5b161a473dba27bc4e576ebbb31a
  • alt-python310-libs_3.10.20-11_amd64.deb
    sha:d7219262e0fafd563d46b31d22b52b5395a0d64c
  • alt-python310-test_3.10.20-11_amd64.deb
    sha:0e99b809ebe7bfd328c863d8cabfd068e8f58eea
  • alt-python310-tkinter_3.10.20-11_amd64.deb
    sha:5638d413ea9e8f52cd3e1e7730d484380fda52d8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.