[CLSA-2026:1786093153] python: Fix of CVE-2026-11972
Type:
security
Severity:
Important
Release date:
2026-08-13 03:09:30 UTC
Description:
- CVE-2026-11972: fix an unbounded loop (CPU DoS) in the tarfile module when a member header in a streaming-mode archive (mode="r|") declares a huge size, by breaking out of the _Stream.seek() read loop at EOF
CVEs fixed:
Updated packages:
  • python-2.6.6-70.el6.tuxcare.els28.i686.rpm
    sha:9f8758d68435b38d02109f97fbe21b215a90aa959904efdc5c0ab9cd36248e80
  • python-2.6.6-70.el6.tuxcare.els28.x86_64.rpm
    sha:63cd6ed711cccf0610a0065e8f21479ffc37a1c8d4f81873062d5a30a89539b2
  • python-devel-2.6.6-70.el6.tuxcare.els28.i686.rpm
    sha:7d562cfb5c2aab0c86ef21171c6b1ed8c0fc86b3e5fb42f97e903c5425f03e59
  • python-devel-2.6.6-70.el6.tuxcare.els28.x86_64.rpm
    sha:76e43499ebaf803e58ca79fd36fb5d6952ef697ef49ded375cfca43c32b58d1a
  • python-libs-2.6.6-70.el6.tuxcare.els28.i686.rpm
    sha:291b2feabab8d3ce588d4ead14db435fa1d721944451db44083aa397077ee4e1
  • python-libs-2.6.6-70.el6.tuxcare.els28.x86_64.rpm
    sha:20518d499a770d9828e007d122abd617ff833907872df4bf4b08105947631b66
  • python-test-2.6.6-70.el6.tuxcare.els28.x86_64.rpm
    sha:fdceeb94135d13b7c8990d49507dad8aa00a38726de8f2e9f3c8e2f4547eae45
  • python-tools-2.6.6-70.el6.tuxcare.els28.x86_64.rpm
    sha:8d7a6dcbe6a068eaf1f0863db395fffb25ba27f92db057f6c50d6101a003d482
  • tkinter-2.6.6-70.el6.tuxcare.els28.x86_64.rpm
    sha:72ba5ad5f9567d76e8bbd8d6e9da702c4ad73ffed408389db953db9b11ad9997
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.