[CLSA-2026:1787227985] Fix CVE(s): CVE-2026-6879
Type:
security
Severity:
Low
Release date:
2026-08-20 12:13:16 UTC
Description:
* SECURITY UPDATE: quadratic complexity in xml.etree XPath index predicates - debian/patches/CVE-2026-6879.patch: cache the indexed sibling lookup in the ElementPath predicate selector so Element.findall() and a fully-consumed Element.iterfind() with an XPath index predicate call parent.findall() once per parent/tag pair instead of once per matching sibling, removing the O(n^2) CPU DoS on documents with many same-tag siblings - CVE-2026-6879
CVEs fixed:
Updated packages:
  • alt-python310_3.10.20-11_amd64.deb
    sha:12909d87a650abcdc06ad8cd8d23a07a3ce9601d
  • alt-python310-debug_3.10.20-11_amd64.deb
    sha:86fedcaa86983defb585029dcf43ff09b38ba3c3
  • alt-python310-devel_3.10.20-11_amd64.deb
    sha:9a5113fccbfc68049a5aa6131ee8a9ff11c0fb09
  • alt-python310-idle_3.10.20-11_amd64.deb
    sha:0978887a47864562dc3e4b50e40ffddc1af1682e
  • alt-python310-libs_3.10.20-11_amd64.deb
    sha:db2c8247fa839cb8ac2af82ce66b68773e21b58a
  • alt-python310-test_3.10.20-11_amd64.deb
    sha:5cf79909877f23d161aff032f5a8af312c476b12
  • alt-python310-tkinter_3.10.20-11_amd64.deb
    sha:85ef08152de1ace23075263f7ea182f5736e5b6b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.