<?xml version='1.0' encoding='UTF-8'?>
<oval_definitions xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>Tuxcare Errata System</oval:product_name>
    <oval:product_version>0.0.1</oval:product_version>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2026-08-12T17:22:55</oval:timestamp>
  </generator>
  <definitions>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1748352587" version="1">
      <metadata>
        <title>alt-python36: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1748352587" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1748352587" source="CLSA"/>
        <reference ref_id="CVE-2023-24329" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-24329" source="CVE"/>
        <reference ref_id="CVE-2024-9287" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-9287" source="CVE"/>
        <reference ref_id="CVE-2024-6232" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-6232" source="CVE"/>
        <reference ref_id="CVE-2022-45061" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-45061" source="CVE"/>
        <reference ref_id="CVE-2023-27043" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-27043" source="CVE"/>
        <reference ref_id="CVE-2023-40217" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-40217" source="CVE"/>
        <reference ref_id="CVE-2021-28861" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2021-28861" source="CVE"/>
        <reference ref_id="CVE-2024-7592" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-7592" source="CVE"/>
        <description>- CVE-2023-24329: make urllib.parse.urlparse enforce that a scheme must
  begin with an alphabetical ASCII character
- CVE-2023-40217: check for &amp; avoid the ssl pre-close flaw
- CVE-2024-6232: remove backtracking when parsing tarfile headers
- CVE-2024-7592: fix quadratic complexity in parsing double-quoted cookie
  values with backslashes</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-05-27"/>
          <updated date="2025-05-27"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-24329" impact="important" public="20230217">CVE-2023-24329</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-428" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-9287" impact="important" public="20241022">CVE-2024-9287</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-6232" impact="important" public="20240903">CVE-2024-6232</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-407" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-45061" impact="important" public="20221109">CVE-2022-45061</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-27043" impact="moderate" public="20230419">CVE-2023-27043</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-40217" impact="moderate" public="20230825">CVE-2023-40217</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" cwe="CWE-601" href="https://cve.tuxcare.com/els-lang/cve/CVE-2021-28861" impact="important" public="20220823">CVE-2021-28861</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-7592" impact="important" public="20240819">CVE-2024-7592</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1748352587001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1748352587003"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1748352587005"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1748352587007"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1748352587009"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1748352587011"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1748352587013"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1749037854" version="1">
      <metadata>
        <title>alt-python36: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1749037854" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1749037854" source="CLSA"/>
        <reference ref_id="CVE-2007-4559" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2007-4559" source="CVE"/>
        <reference ref_id="CVE-2023-6597" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-6597" source="CVE"/>
        <description>- CVE-2007-4559: implement PEP 706 - a filter in the tarfile module to
  prevent directory traversal vulnerability
- CVE-2023-6597: prevent tempfile.TemporaryDirectory class dereference
  symlinks</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-06-04"/>
          <updated date="2025-06-04"/>
          <cve cvss2="6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P" cwe="CWE-22" href="https://cve.tuxcare.com/els-lang/cve/CVE-2007-4559" impact="moderate" public="20070828">CVE-2007-4559</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" cwe="CWE-61" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-6597" impact="important" public="20240319">CVE-2023-6597</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-7.el9" test_ref="oval:com.tuxcare.clsa:tst:1749037854001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-7.el9" test_ref="oval:com.tuxcare.clsa:tst:1749037854002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-7.el9" test_ref="oval:com.tuxcare.clsa:tst:1749037854003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-7.el9" test_ref="oval:com.tuxcare.clsa:tst:1749037854004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-7.el9" test_ref="oval:com.tuxcare.clsa:tst:1749037854005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-7.el9" test_ref="oval:com.tuxcare.clsa:tst:1749037854006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-7.el9" test_ref="oval:com.tuxcare.clsa:tst:1749037854007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1753205878" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2019-9674</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1753205878" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1753205878" source="CLSA"/>
        <reference ref_id="CVE-2019-9674" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" source="CVE"/>
        <description>- CVE-2019-9674: add pitfalls to zipfile module documentation</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-07-22"/>
          <updated date="2025-07-22"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" impact="important" public="20200204">CVE-2019-9674</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-8.el9" test_ref="oval:com.tuxcare.clsa:tst:1753205878001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-8.el9" test_ref="oval:com.tuxcare.clsa:tst:1753205878002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-8.el9" test_ref="oval:com.tuxcare.clsa:tst:1753205878003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-8.el9" test_ref="oval:com.tuxcare.clsa:tst:1753205878004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-8.el9" test_ref="oval:com.tuxcare.clsa:tst:1753205878005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-8.el9" test_ref="oval:com.tuxcare.clsa:tst:1753205878006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-8.el9" test_ref="oval:com.tuxcare.clsa:tst:1753205878007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1753804881" version="1">
      <metadata>
        <title>alt-python27: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1753804881" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1753804881" source="CLSA"/>
        <reference ref_id="CVE-2024-7592" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-7592" source="CVE"/>
        <reference ref_id="CVE-2024-6232" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2024-6232" source="CVE"/>
        <reference ref_id="CVE-2023-24329" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-24329" source="CVE"/>
        <reference ref_id="CVE-2019-9674" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" source="CVE"/>
        <reference ref_id="CVE-2022-48560" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-48560" source="CVE"/>
        <reference ref_id="CVE-2022-48565" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-48565" source="CVE"/>
        <reference ref_id="CVE-2022-45061" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-45061" source="CVE"/>
        <reference ref_id="CVE-2022-0391" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-0391" source="CVE"/>
        <description>- CVE-2022-45061: fix quadratic time idna decoding
- CVE-2019-9674: add pitfalls to zipfile module documentation</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-07-29"/>
          <updated date="2025-07-29"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-7592" impact="important" public="20240819">CVE-2024-7592</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-lang/cve/CVE-2024-6232" impact="important" public="20240903">CVE-2024-6232</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-24329" impact="important" public="20230217">CVE-2023-24329</cve>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-lang/cve/CVE-2019-9674" impact="important" public="20200204">CVE-2019-9674</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-48560" impact="important" public="20230822">CVE-2022-48560</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-48565" impact="critical" public="20230822">CVE-2022-48565</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-45061" impact="important" public="20221109">CVE-2022-45061</cve>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-0391" impact="important" public="20220209">CVE-2022-0391</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-14.el9" test_ref="oval:com.tuxcare.clsa:tst:1753804881001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-14.el9" test_ref="oval:com.tuxcare.clsa:tst:1753804881003"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-14.el9" test_ref="oval:com.tuxcare.clsa:tst:1753804881005"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-14.el9" test_ref="oval:com.tuxcare.clsa:tst:1753804881007"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-14.el9" test_ref="oval:com.tuxcare.clsa:tst:1753804881009"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-14.el9" test_ref="oval:com.tuxcare.clsa:tst:1753804881011"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-14.el9" test_ref="oval:com.tuxcare.clsa:tst:1753804881013"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1754039871" version="1">
      <metadata>
        <title>alt-python27: Fix of 3 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1754039871" ref_url="https://cve.tuxcare.com/els-lang/releases/CLSA-2025:1754039871" source="CLSA"/>
        <reference ref_id="CVE-2020-8492" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2020-8492" source="CVE"/>
        <reference ref_id="CVE-2022-48566" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2022-48566" source="CVE"/>
        <reference ref_id="CVE-2023-40217" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-40217" source="CVE"/>
        <reference ref_id="CVE-2021-3733" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2021-3733" source="CVE"/>
        <reference ref_id="CVE-2023-27043" ref_url="https://cve.tuxcare.com/els-lang/cve/CVE-2023-27043" source="CVE"/>
        <description>- CVE-2023-27043: reject malformed addresses in email.parseaddr()
- CVE-2020-8492: fix regex in AbstractBasicAuthHandler
- CVE-2021-3733: fix regex in AbstractBasicAuthHandler</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-08-01"/>
          <updated date="2025-08-01"/>
          <cve cvss2="7.1/AV:N/AC:M/Au:N/C:N/I:N/A:C" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-lang/cve/CVE-2020-8492" impact="moderate" public="20200130">CVE-2020-8492</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-362" href="https://cve.tuxcare.com/els-lang/cve/CVE-2022-48566" impact="moderate" public="20230822">CVE-2022-48566</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-40217" impact="moderate" public="20230825">CVE-2023-40217</cve>
          <cve cvss2="4.0/AV:N/AC:L/Au:S/C:N/I:N/A:P" cvss3="6.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-lang/cve/CVE-2021-3733" impact="moderate" public="20220310">CVE-2021-3733</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-lang/cve/CVE-2023-27043" impact="moderate" public="20230419">CVE-2023-27043</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1754039871001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1754039871002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1754039871003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1754039871004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1754039871005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1754039871006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1754039871007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760098218" version="1">
      <metadata>
        <title>alt-python27: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760098218" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760098218" source="CLSA"/>
        <reference ref_id="CVE-2019-20907" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-20907" source="CVE"/>
        <reference ref_id="CVE-2021-3737" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3737" source="CVE"/>
        <description>- CVE-2021-3737: stop reading a header if it's too long
- CVE-2019-20907: avoid infinite loop in the tarfile module
- Build and testing fixes in spec</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-10"/>
          <updated date="2025-10-10"/>
          <cve cvss2="5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-20907" impact="important" public="20200713">CVE-2019-20907</cve>
          <cve cvss2="7.1/AV:N/AC:M/Au:N/C:N/I:N/A:C" cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3737" impact="important" public="20220304">CVE-2021-3737</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1760098218001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1760098218002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1760098218003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1760098218004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1760098218005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1760098218006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1760098218007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1760369183" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2020-26116</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1760369183" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1760369183" source="CLSA"/>
        <reference ref_id="CVE-2020-26116" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-26116" source="CVE"/>
        <description>- CVE-2020-26116: prevent http header injection in httplib</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-10-13"/>
          <updated date="2025-10-13"/>
          <cve cvss2="6.4/AV:N/AC:L/Au:N/C:P/I:P/A:N" cvss3="7.2/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-26116" impact="important" public="20200927">CVE-2020-26116</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1760369183001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1760369183002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1760369183003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1760369183004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1760369183005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1760369183006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1760369183007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1762528386" version="1">
      <metadata>
        <title>alt-python36: Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2025:1762528386" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2025:1762528386" source="CLSA"/>
        <reference ref_id="CVE-2025-4435" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" source="CVE"/>
        <reference ref_id="CVE-2025-4330" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" source="CVE"/>
        <reference ref_id="CVE-2025-4138" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" source="CVE"/>
        <reference ref_id="CVE-2024-12718" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" source="CVE"/>
        <reference ref_id="CVE-2025-4517" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" source="CVE"/>
        <description>- Fix CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435,
  CVE-2025-4517: fix multiple tarfile extraction filter bypasses
  (filter="tar"/filter="data")
- fix test_tarfile.py</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2025-11-07"/>
          <updated date="2025-11-07"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-706" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" impact="important" public="20250603">CVE-2025-4435</cve>
          <cve cvss3="7.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" impact="important" public="20250603">CVE-2025-4330</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" impact="important" public="20250603">CVE-2025-4138</cve>
          <cve cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" impact="important" public="20250603">CVE-2024-12718</cve>
          <cve cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" impact="important" public="20250603">CVE-2025-4517</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-13.el9" test_ref="oval:com.tuxcare.clsa:tst:1762528386001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-13.el9" test_ref="oval:com.tuxcare.clsa:tst:1762528386002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-13.el9" test_ref="oval:com.tuxcare.clsa:tst:1762528386003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-13.el9" test_ref="oval:com.tuxcare.clsa:tst:1762528386004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-13.el9" test_ref="oval:com.tuxcare.clsa:tst:1762528386005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-13.el9" test_ref="oval:com.tuxcare.clsa:tst:1762528386006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-13.el9" test_ref="oval:com.tuxcare.clsa:tst:1762528386007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1771339135" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2025-13837</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1771339135" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1771339135" source="CLSA"/>
        <reference ref_id="CVE-2025-13837" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" source="CVE"/>
        <description>- CVE-2025-13837: fix memory denial of service in plistlib</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-17"/>
          <updated date="2026-02-17"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" impact="moderate" public="20251201">CVE-2025-13837</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1771339135001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1771339135002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1771339135003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1771339135004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1771339135005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1771339135006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-16.el9" test_ref="oval:com.tuxcare.clsa:tst:1771339135007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772111352" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2015-20107</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772111352" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772111352" source="CLSA"/>
        <reference ref_id="CVE-2015-20107" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" source="CVE"/>
        <description>- CVE-2015-20107: mailcap: sanitize the second argument which allowing
  shell commands injection</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-26"/>
          <updated date="2026-02-26"/>
          <cve cvss2="8.0/AV:N/AC:L/Au:S/C:P/I:C/A:P" cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" impact="important" public="20220413">CVE-2015-20107</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1772111352001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1772111352002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1772111352003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1772111352004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1772111352005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1772111352006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1772111352007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772139704" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2015-20107</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772139704" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772139704" source="CLSA"/>
        <reference ref_id="CVE-2015-20107" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" source="CVE"/>
        <description>- CVE-2015-20107: sanitize the second argument, which allows shell
  command injection in the mailcap module</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-26"/>
          <updated date="2026-02-26"/>
          <cve cvss2="8.0/AV:N/AC:L/Au:S/C:P/I:C/A:P" cvss3="7.6/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2015-20107" impact="important" public="20220413">CVE-2015-20107</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1772139704001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1772139704002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1772139704003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1772139704004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1772139704005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1772139704006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1772139704007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772188508" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2025-12084</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772188508" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772188508" source="CLSA"/>
        <reference ref_id="CVE-2025-12084" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" source="CVE"/>
        <description>- CVE-2025-12084: remove quadratic behavior in xml.minidom
  node ID cache clearing</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-02-27"/>
          <updated date="2026-02-27"/>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" impact="moderate" public="20251203">CVE-2025-12084</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1772188508001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1772188508002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1772188508003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1772188508004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1772188508005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1772188508006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1772188508007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772446514" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2025-6075</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772446514" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772446514" source="CLSA"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <description>- CVE-2025-6075: fix quadratic complexity in os.path.expandvars()</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-02"/>
          <updated date="2026-03-02"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-18.el9" test_ref="oval:com.tuxcare.clsa:tst:1772446514001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-18.el9" test_ref="oval:com.tuxcare.clsa:tst:1772446514002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-18.el9" test_ref="oval:com.tuxcare.clsa:tst:1772446514003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-18.el9" test_ref="oval:com.tuxcare.clsa:tst:1772446514004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-18.el9" test_ref="oval:com.tuxcare.clsa:tst:1772446514005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-18.el9" test_ref="oval:com.tuxcare.clsa:tst:1772446514006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-18.el9" test_ref="oval:com.tuxcare.clsa:tst:1772446514007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772559514" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2025-8194</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772559514" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772559514" source="CLSA"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <description>- CVE-2025-8194: tarfile: validate archives to ensure member offsets are
  non-negative</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-03"/>
          <updated date="2026-03-03"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1772559514001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1772559514002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1772559514003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1772559514004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1772559514005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1772559514006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1772559514007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1772721745" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2025-8194</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1772721745" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1772721745" source="CLSA"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <description>- CVE-2025-8194: tarfile: validate archives to ensure member offsets are
  non-negative</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-05"/>
          <updated date="2026-03-05"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1772721745001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1772721745002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1772721745003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1772721745004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1772721745005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1772721745006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1772721745007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1773240322" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2025-6075</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1773240322" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1773240322" source="CLSA"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <description>- CVE-2025-6075: fix quadratic complexity in os.path.expandvars()</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-03-11"/>
          <updated date="2026-03-11"/>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1773240322001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1773240322002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1773240322003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1773240322004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1773240322005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1773240322006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1773240322007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1776434771" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2026-4519</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1776434771" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1776434771" source="CLSA"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <description>- CVE-2026-4519: reject leading dashes in webbrowser.open() URLs to prevent command-line option injection in browser subprocesses</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-17"/>
          <updated date="2026-04-17"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="low" public="20260320">CVE-2026-4519</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1776434771001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1776434771002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1776434771003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1776434771004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1776434771005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1776434771006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1776434771007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777047108" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2026-4519</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777047108" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777047108" source="CLSA"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <description>- CVE-2026-4519: reject leading dashes in webbrowser.open() URLs to prevent command-line option injection in browser subprocesses</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-24"/>
          <updated date="2026-04-24"/>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-27.el9" test_ref="oval:com.tuxcare.clsa:tst:1777047108001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-27.el9" test_ref="oval:com.tuxcare.clsa:tst:1777047108002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-27.el9" test_ref="oval:com.tuxcare.clsa:tst:1777047108003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-27.el9" test_ref="oval:com.tuxcare.clsa:tst:1777047108004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-27.el9" test_ref="oval:com.tuxcare.clsa:tst:1777047108005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-27.el9" test_ref="oval:com.tuxcare.clsa:tst:1777047108006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-27.el9" test_ref="oval:com.tuxcare.clsa:tst:1777047108007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777390475" version="1">
      <metadata>
        <title>alt-python36: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777390475" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777390475" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2024-0450" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" source="CVE"/>
        <description>- CVE-2024-0450: zipfile raises BadZipFile on quoted-overlap archive
  entries to prevent high-ratio zip bombs
- CVE-2026-6100: use-after-free in lzma/bz2 decompressors when a
  MemoryError leaves a stale next_in pointer on a re-used decompressor</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-28"/>
          <updated date="2026-04-28"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-450" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" impact="moderate" public="20240319">CVE-2024-0450</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1777390475001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1777390475002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1777390475003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1777390475004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1777390475005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1777390475006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1777390475007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777478783" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2026-6100</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777478783" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777478783" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2020-27619" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619" source="CVE"/>
        <reference ref_id="CVE-2024-0450" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" source="CVE"/>
        <reference ref_id="CVE-2021-3177" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177" source="CVE"/>
        <reference ref_id="CVE-2021-4189" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-4189" source="CVE"/>
        <description>- CVE-2026-6100: NULL bzs-&gt;next_in in error paths in
  BZ2Decomp_decompress.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-04-29"/>
          <updated date="2026-04-29"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619" impact="critical" public="20201022">CVE-2020-27619</cve>
          <cve cvss3="6.2/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-450" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0450" impact="moderate" public="20240319">CVE-2024-0450</cve>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-120" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177" impact="critical" public="20210119">CVE-2021-3177</cve>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-4189" impact="moderate" public="20220824">CVE-2021-4189</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1777478783001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1777478783002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1777478783003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1777478783004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1777478783005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1777478783006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1777478783007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777630510" version="1">
      <metadata>
        <title>alt-python27: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777630510" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777630510" source="CLSA"/>
        <reference ref_id="CVE-2024-6923" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" source="CVE"/>
        <reference ref_id="CVE-2021-28861" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-28861" source="CVE"/>
        <reference ref_id="CVE-2024-0397" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <description>- CVE-2026-1299: email.Generator now rejects header *values* containing
  CR/LF that are not followed by folding whitespace by raising
  HeaderWriteError. In Python 2.7 (which lacks BytesGenerator) this
  single Generator-class hardening covers both upstream CVE-2026-1299
  and CVE-2024-6923.
- CVE-2024-6923: email.Generator now rejects header *names* containing
  CR/LF that are not followed by folding whitespace by raising
  HeaderWriteError, preventing header injection through the header
  name.
- CVE-2024-0397: ssl.SSLContext.cert_store_stats and get_ca_certs now
  deep-copy the X509_STORE under X509_STORE_lock (via a backport of
  OpenSSL 3.3's X509_STORE_get1_objects), fixing a memory race when an
  SSLContext is shared across threads.
- CVE-2021-28861: BaseHTTPServer now collapses any leading run of '/'
  in the request path to a single '/' to prevent an open-redirect via
  //evil.example/... URIs in 301 Location headers.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-01"/>
          <updated date="2026-05-01"/>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" impact="moderate" public="20240801">CVE-2024-6923</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" cwe="CWE-601" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-28861" impact="important" public="20220823">CVE-2021-28861</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" impact="important" public="20240617">CVE-2024-0397</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1777630510001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1777630510002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1777630510003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1777630510004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1777630510005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1777630510006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1777630510007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1777637454" version="1">
      <metadata>
        <title>alt-python36: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1777637454" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1777637454" source="CLSA"/>
        <reference ref_id="CVE-2024-4032" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-4032" source="CVE"/>
        <reference ref_id="CVE-2024-0397" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <description>- CVE-2026-1299: email.BytesGenerator now refuses to serialize headers
  that are unsafely folded or contain unfolded newlines, closing a
  header-injection bypass of CVE-2024-6923 (also includes the
  CVE-2024-6923 prerequisite hardening of the string Generator)
- CVE-2024-0397: ssl.SSLContext.cert_store_stats() and get_ca_certs()
  now correctly lock the certificate store via a backported
  X509_STORE_get1_objects shim, fixing a memory race when an
  SSLContext is shared across threads
- CVE-2024-4032: ipaddress is_private/is_global now classify addresses
  per the IANA special-purpose registries (192.0.0.0/24 with 192.0.0.9
  and 192.0.0.10 exceptions, 64:ff9b:1::/48, 2002::/16, and the
  2001::/23 sub-range exceptions)</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-01"/>
          <updated date="2026-05-01"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-440" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-4032" impact="important" public="20240617">CVE-2024-4032</cve>
          <cve cvss3="7.4/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" cwe="CWE-362" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-0397" impact="important" public="20240617">CVE-2024-0397</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1777637454001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1777637454002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1777637454003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1777637454004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1777637454005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1777637454006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1777637454007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1778161965" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2026-3446</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1778161965" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1778161965" source="CLSA"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <description>- CVE-2026-3446: binascii.a2b_base64 / base64.b64decode no longer abort the
  decoder loop on the first padded quad. The pad character is treated as
  non-alphabet data per RFC 4648 section 3.3, so excess data after the
  padding is decoded instead of being silently dropped.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-07"/>
          <updated date="2026-05-07"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1778161965001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1778161965002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1778161965003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1778161965004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1778161965005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1778161965006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-23.el9" test_ref="oval:com.tuxcare.clsa:tst:1778161965007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1778245330" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2026-3446</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1778245330" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1778245330" source="CLSA"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <description>- CVE-2026-3446: binascii.a2b_base64 / base64.b64decode no longer abort the
  decoder loop on the first padded quad. The pad character is treated as
  non-alphabet data per RFC 4648 section 3.3, so excess data after the
  padding is decoded instead of being silently dropped.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-08"/>
          <updated date="2026-05-08"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1778245330001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1778245330002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1778245330003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1778245330004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1778245330005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1778245330006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1778245330007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779278705" version="1">
      <metadata>
        <title>alt-python36: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779278705" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779278705" source="CLSA"/>
        <reference ref_id="CVE-2025-15282" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <description>- CVE-2025-15282: urllib.request.DataHandler accepted data: URLs whose
  mediatype contained C0 control characters, allowing newline-based HTTP
  header injection downstream. Reject control characters in data_open().
- CVE-2026-0672: http.cookies.Morsel did not reject control characters in
  keys, values, or coded_value, allowing cookie injection via __setitem__,
  setdefault, set, and BaseCookie.output. Add a _has_control_character
  helper and validate in those entry points and BaseCookie.OutputString.
- CVE-2026-3644: the CVE-2026-0672 fix was incomplete; control characters
  could still bypass via Morsel.update(), |=, __setstate__, and
  BaseCookie.js_output(). Validate those entry points too and re-validate
  the assembled output string in js_output().
- CVE-2026-4224: Modules/pyexpat.c conv_content_model could overflow the
  C stack when an Expat parser with a registered ElementDeclHandler
  parsed a deeply nested DTD content model, causing a denial-of-service.
  Wrap conv_content_model with Py_EnterRecursiveCall so deep nesting
  raises RecursionError instead of crashing.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-20"/>
          <updated date="2026-05-20"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" impact="moderate" public="20260120">CVE-2025-15282</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" cwe="CWE-791" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="moderate" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-805" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="moderate" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1779278705001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1779278705002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1779278705003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1779278705004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1779278705005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1779278705006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1779278705007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779463938" version="1">
      <metadata>
        <title>alt-python27: Fix of 3 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779463938" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779463938" source="CLSA"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <description>- CVE-2026-4224: Modules/pyexpat.c conv_content_model could overflow the
  C stack when an Expat parser with a registered ElementDeclHandler
  parsed a deeply nested DTD content model, causing a denial-of-service.
  Wrap conv_content_model with Py_EnterRecursiveCall so deep nesting
  raises RuntimeError instead of crashing.
- CVE-2026-0672 + CVE-2026-3644: Lib/Cookie.py Morsel accepted control
  characters in reserved-attribute values, in key/value/coded_value
  via .set(), and via the inherited dict.update() / pickle restoration
  paths, allowing newline-based HTTP header injection via Set-Cookie.
  Add a _has_control_character helper and validate at Morsel.__setitem__,
  .setdefault, .set, an explicit .update, an explicit .__setstate__, plus
  re-validate the assembled output in Morsel.js_output and
  BaseCookie.output (defence-in-depth against direct attribute mutation).
  The py3 __ior__ hunk is not ported (py2 dict has no `|=` operator).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-22"/>
          <updated date="2026-05-22"/>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" cwe="CWE-791" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="moderate" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-805" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="moderate" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-32.el9" test_ref="oval:com.tuxcare.clsa:tst:1779463938001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-32.el9" test_ref="oval:com.tuxcare.clsa:tst:1779463938002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-32.el9" test_ref="oval:com.tuxcare.clsa:tst:1779463938003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-32.el9" test_ref="oval:com.tuxcare.clsa:tst:1779463938004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-32.el9" test_ref="oval:com.tuxcare.clsa:tst:1779463938005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-32.el9" test_ref="oval:com.tuxcare.clsa:tst:1779463938006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-32.el9" test_ref="oval:com.tuxcare.clsa:tst:1779463938007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779880402" version="1">
      <metadata>
        <title>alt-python36: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779880402" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779880402" source="CLSA"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>- CVE-2026-7210 + CVE-2026-41080 (paired): backport libexpat 16-byte
  salt API (XML_SetHashSalt16Bytes) into bundled expat 2.4.1 and wire
  pyexpat/_elementtree to use it. Together these restore proper
  hash-flood mitigation for xml.parsers.expat and
  xml.etree.ElementTree.
    CVE-2026-7210 (cpython 24b8f12): xml.parsers.expat and
  xml.etree.ElementTree used insufficient entropy (a single Py_hash_t)
  for Expat hash-flooding protection. The cpython half of the fix
  seeds the parser with the full 16-byte
  _Py_HashSecret.expat.hashsalt16 via XML_SetHashSalt16Bytes when the
  libexpat being linked exposes that API.
    CVE-2026-41080 (libexpat PR #1183): libexpat's hash-flood
  protection itself only used 4-8 bytes of entropy for the SipHash
  salt. The libexpat half adds the new XML_SetHashSalt16Bytes API
  (and widens the parser's internal salt storage to a full
  struct sipkey) so the 16-byte path is available. Backported into
  the bundled libexpat 2.4.1 tree in Modules/expat/; the bundled
  expat.h now also defines XML_HAS_HASHSALT16BYTES_BACKPORT so the
  cpython 20800 gate activates against the patched bundle without
  bumping the advertised libexpat version. Alpine builds use
  --with-system-expat and are unaffected by the libexpat backport.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-27"/>
          <updated date="2026-05-27"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="critical" public="20260511">CVE-2026-7210</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1779880402001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1779880402002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1779880402003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1779880402004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1779880402005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1779880402006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-25.el9" test_ref="oval:com.tuxcare.clsa:tst:1779880402007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1779887983" version="1">
      <metadata>
        <title>alt-python27: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1779887983" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1779887983" source="CLSA"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>- CVE-2026-7210 + CVE-2026-41080 (paired): backport libexpat 16-byte
  salt API (XML_SetHashSalt16Bytes) into bundled expat 2.2.8 and wire
  pyexpat/_elementtree to use it. Together these restore proper
  hash-flood mitigation.
  * CVE-2026-7210 (cpython side, gh-149018 / 24b8f12): xml.parsers.expat
    and xml.etree.ElementTree used the legacy 8-byte XML_SetHashSalt
    API, which can be brute-forced to trigger hash collisions. Adds a
    hashsalt16[16] field to _Py_HashSecret_t in Include/object.h
    (seeded by _PyRandom_Init), exposes a NULL-able SetHashSalt16Bytes
    function pointer in the pyexpat CAPI struct, and prefers the new
    16-byte API whenever XML_COMBINED_VERSION &gt;= 20800.
  * CVE-2026-41080 (libexpat side, PR #1183): widens m_hash_secret_salt
    in the bundled libexpat 2.2.8 source tree (Modules/expat/) from
    `unsigned long` to a `struct sipkey` (128 bits) and adds the new
    public XML_SetHashSalt16Bytes() entry point. The bundled
    pyexpat.so / _elementtree.so are statically linked against this
    tree, so the cpython half can now consume full 16-byte entropy in
    every build configuration (no external libexpat &gt;= 2.8.0
    requirement).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-05-27"/>
          <updated date="2026-05-27"/>
          <cve cvss3="9.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="critical" public="20260511">CVE-2026-7210</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-33.el9" test_ref="oval:com.tuxcare.clsa:tst:1779887983001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-33.el9" test_ref="oval:com.tuxcare.clsa:tst:1779887983002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-33.el9" test_ref="oval:com.tuxcare.clsa:tst:1779887983003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-33.el9" test_ref="oval:com.tuxcare.clsa:tst:1779887983004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-33.el9" test_ref="oval:com.tuxcare.clsa:tst:1779887983005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-33.el9" test_ref="oval:com.tuxcare.clsa:tst:1779887983006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-33.el9" test_ref="oval:com.tuxcare.clsa:tst:1779887983007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1780516373" version="1">
      <metadata>
        <title>alt-python36: Fix of 12 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1780516373" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1780516373" source="CLSA"/>
        <reference ref_id="CVE-2025-4516" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" source="CVE"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2024-50602" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" source="CVE"/>
        <reference ref_id="CVE-2024-11168" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" source="CVE"/>
        <reference ref_id="CVE-2026-0865" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" source="CVE"/>
        <reference ref_id="CVE-2025-8291" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" source="CVE"/>
        <reference ref_id="CVE-2025-6069" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" source="CVE"/>
        <reference ref_id="CVE-2025-1795" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" source="CVE"/>
        <reference ref_id="CVE-2025-0938" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <reference ref_id="CVE-2025-11468" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" source="CVE"/>
        <description>- CVE-2025-13462: tarfile applied AREGTYPE -&gt; DIRTYPE normalization even
  during multi-block GNU long members (LONGNAME / LONGLINK), enabling a
  parsing differential. Thread a dircheck flag through frombuf /
  fromtarfile so normalization is skipped on follow-up headers.
- CVE-2026-0865: wsgiref.headers.Headers did not reject control characters
  in header names / values, allowing HTTP header injection from WSGI
  applications. Combined backport: gh-143917 adds the control-char
  regex check, gh-143916 HTAB follow-up splits the check so HTAB is
  allowed in header values (RFC 9110 Section 5.5) but still rejected
  in header names; LF / CR / DEL remain rejected in both. gh-144370
  also disallows control characters in status in wsgiref.handlers.
- CVE-2026-1502: http.client did not reject CR/LF in HTTPConnection
  CONNECT tunnel host / headers, enabling request injection. Validate the
  tunnel host and per-header name / value in _tunnel().
- CVE-2026-6019: http.cookies.Morsel.js_output() emitted an inline
  &lt;script&gt; snippet that only escaped " and left &lt;/script&gt; intact,
  enabling HTML injection. Base64-encode the cookie value in the
  emitted JavaScript (gh-90309).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-03"/>
          <updated date="2026-06-03"/>
          <cve cvss3="5.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" impact="moderate" public="20250515">CVE-2025-4516</cve>
          <cve cvss3="2.5/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-237" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-754" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" impact="moderate" public="20241027">CVE-2024-50602</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" impact="moderate" public="20241112">CVE-2024-11168</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" impact="moderate" public="20260120">CVE-2026-0865</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-130" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" impact="moderate" public="20251007">CVE-2025-8291</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" impact="moderate" public="20250617">CVE-2025-6069</cve>
          <cve cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-168" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" impact="low" public="20250228">CVE-2025-1795</cve>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" impact="moderate" public="20250131">CVE-2025-0938</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-140" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" impact="moderate" public="20260120">CVE-2025-11468</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-28.el9" test_ref="oval:com.tuxcare.clsa:tst:1780516373001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-28.el9" test_ref="oval:com.tuxcare.clsa:tst:1780516373002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-28.el9" test_ref="oval:com.tuxcare.clsa:tst:1780516373003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-28.el9" test_ref="oval:com.tuxcare.clsa:tst:1780516373004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-28.el9" test_ref="oval:com.tuxcare.clsa:tst:1780516373005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-28.el9" test_ref="oval:com.tuxcare.clsa:tst:1780516373006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-28.el9" test_ref="oval:com.tuxcare.clsa:tst:1780516373007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1781103532" version="1">
      <metadata>
        <title>alt-python27: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1781103532" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1781103532" source="CLSA"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <description>- CVE-2025-15366: imaplib.IMAP4._command() concatenated each argument
  into the wire-level command without inspecting it, so user-controlled
  text (e.g. a username passed to IMAP4.login()) containing CR/LF or
  other control characters could inject a second IMAP command. A
  module-level _control_chars regex and a guard in _command() now reject
  any argument containing a byte in [\x00-\x1F\x7F] with ValueError
  before concatenation.
- CVE-2025-15367: poplib.POP3._putcmd() sent its argument to the server
  without inspecting it, so user-controlled text passed to
  user()/pass_()/apop()/rpop()/top() could inject a second POP3 command.
  _putcmd() now rejects any argument containing a byte in [\x00-\x1F\x7F]
  with ValueError before sending.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-10"/>
          <updated date="2026-06-10"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1781103532001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1781103532002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1781103532003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1781103532004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1781103532005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1781103532006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1781103532007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1781521190" version="1">
      <metadata>
        <title>alt-python36: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1781521190" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1781521190" source="CLSA"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <description>- CVE-2025-15366: imaplib.IMAP4._command() concatenated each command
  argument into the wire-level command without inspecting it, so a caller
  passing user-controlled text could inject extra IMAP commands using
  CR/LF or other control characters. Reject any byte in [\x00-\x1F\x7F]
  with ValueError before concatenation (upstream gh-143921 /
  6262704b; mirrors RHSA-2026:6464 python3-3.6.8-21.el7_9.4).
- CVE-2025-15367: poplib.POP3._putcmd() encoded its argument and sent it
  to the server without inspecting it, allowing the same command
  injection via user()/pass_()/apop()/rpop()/top(). Reject any byte in
  [\x00-\x1F\x7F] with ValueError before sending (upstream gh-143923 /
  b234a2b6; mirrors RHSA-2026:6464 python3-3.6.8-21.el7_9.4).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-15"/>
          <updated date="2026-06-15"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1781521190001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1781521190002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1781521190003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1781521190004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1781521190005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1781521190006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-29.el9" test_ref="oval:com.tuxcare.clsa:tst:1781521190007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1782297615" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2026-9669</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1782297615" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1782297615" source="CLSA"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <description>- CVE-2026-9669: the bz2 BZ2Decompressor could be reused after a libbz2
  decompression error; re-entering BZ2_bzDecompress() in that state can
  write past the end of a stack buffer (CWE-121). The decompressor now
  records the libbz2 error and refuses further decompress() calls with
  ValueError, becoming unusable after the first error (upstream gh-150599
  / 5755d0f0, adapted to 3.6: plain needs_input reset and existing
  ACQUIRE_LOCK/RELEASE_LOCK wrappers, NEWS.d fragment omitted).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-06-24"/>
          <updated date="2026-06-24"/>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1782297615001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1782297615002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1782297615003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1782297615004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1782297615005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1782297615006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-30.el9" test_ref="oval:com.tuxcare.clsa:tst:1782297615007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1782998840" version="1">
      <metadata>
        <title>alt-python27: Fix of 3 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1782998840" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1782998840" source="CLSA"/>
        <reference ref_id="CVE-2024-50602" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" source="CVE"/>
        <reference ref_id="CVE-2024-11168" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" source="CVE"/>
        <reference ref_id="CVE-2025-0938" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" source="CVE"/>
        <description>- CVE-2024-11168: urlparse.urlsplit() did not validate the content of
  bracketed hosts, so domain names that are neither valid IPv6 nor
  IPvFuture literals were accepted inside "[" "]". A new
  _check_bracketed_host() is added (Lib/urlparse.py) and called from
  both the "http" fast-path and the generic branch of urlsplit().
  Python 2.7 has no ipaddress module, so the bracket content is
  validated with socket.inet_pton() (IPv4 in brackets is rejected;
  otherwise the content must parse as IPv6).
- CVE-2024-50602: a NULL pointer dereference in the bundled libexpat
  (Modules/expat/, 2.2.8) when XML_StopParser() was called on a parser
  in the XML_INITIALIZED state followed by XML_ResumeParser().
  XML_StopParser() now refuses to stop/suspend an unstarted parser,
  returning the new XML_ERROR_NOT_STARTED. Backport of libexpat PR
  - CVE-2025-0938: completes CVE-2024-11168 by also rejecting square
  brackets in plain domain names. _check_bracketed_netloc()
  (Lib/urlparse.py) mirrors NetlocResultMixins._hostinfo() so data
  before/after the brackets is rejected; it replaces the inline
  bracket extraction in both branches of urlsplit().</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-02"/>
          <updated date="2026-07-02"/>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-754" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-50602" impact="moderate" public="20241027">CVE-2024-50602</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" impact="moderate" public="20241112">CVE-2024-11168</cve>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" impact="moderate" public="20250131">CVE-2025-0938</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-35.el9" test_ref="oval:com.tuxcare.clsa:tst:1782998840001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-35.el9" test_ref="oval:com.tuxcare.clsa:tst:1782998840002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-35.el9" test_ref="oval:com.tuxcare.clsa:tst:1782998840003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-35.el9" test_ref="oval:com.tuxcare.clsa:tst:1782998840004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-35.el9" test_ref="oval:com.tuxcare.clsa:tst:1782998840005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-35.el9" test_ref="oval:com.tuxcare.clsa:tst:1782998840006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-35.el9" test_ref="oval:com.tuxcare.clsa:tst:1782998840007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1783343295" version="1">
      <metadata>
        <title>alt-python27: Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1783343295" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1783343295" source="CLSA"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2026-0865" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" source="CVE"/>
        <reference ref_id="CVE-2025-8291" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" source="CVE"/>
        <reference ref_id="CVE-2013-0340" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2013-0340" source="CVE"/>
        <reference ref_id="CVE-2025-6069" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <description>- CVE-2013-0340: backport libexpat's billion-laughs / internal-entity-expansion
  amplification protection into the bundled expat 2.2.8 tree (Modules/expat/).
  xmlparse.c/expat.h/internal.h gain the libexpat 2.4.0 accounting machinery
  (XML_SetBillionLaughsAttackProtectionMaximumAmplification /
  ...ActivationThreshold, default 100x after 8 MiB) and a new
  XML_ERROR_AMPLIFICATION_LIMIT_BREACH; entity expansion that exceeds the
  amplification limit is now rejected instead of expanding unbounded. Adapted
  to coexist with the CloudLinux XML_SetHashSalt16Bytes extension; the system
  expat is NOT used. New public symbols are namespaced in pyexpatns.h.
- CVE-2026-0865: reject C0/DEL control characters in wsgiref.headers.Headers
  (Lib/wsgiref/headers.py); HTAB stays legal in values but not names. Backport
  of gh-143916 (GH-143917) plus the HTAB follow-up (GH-144762).
- CVE-2026-1502: reject CR/LF and other illegal characters in HTTP CONNECT
  tunnel host and request headers in HTTPConnection._tunnel()
  (Lib/httplib.py), using the existing _contains_disallowed_url_pchar_re /
  _is_legal_header_name / _is_illegal_header_value helpers. Backport of
  gh-146211 (GH-146212).
- CVE-2026-6019: base64-encode the cookie value embedded in
  Cookie.Morsel.js_output() and emit it via atob() to prevent template
  injection (Lib/Cookie.py). Backport of gh-90309 (GH-148889), on top of
  CVE-2026-3644.
- CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression
  error (Modules/bz2module.c). After libbz2 reports an error the stream is
  inconsistent and re-entering it can overflow the output buffer; the
  decompressor now records the error and raises ValueError on any further
  decompress() call. Port of gh-150599 (GH-150600) to the 2.7 bz2 wrapper.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-06"/>
          <updated date="2026-07-06"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" impact="moderate" public="20260120">CVE-2026-0865</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-130" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" impact="moderate" public="20251007">CVE-2025-8291</cve>
          <cve cwe="CWE-611" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2013-0340" impact="unknown" public="20140121">CVE-2013-0340</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" impact="moderate" public="20250617">CVE-2025-6069</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-37.el9" test_ref="oval:com.tuxcare.clsa:tst:1783343295001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-37.el9" test_ref="oval:com.tuxcare.clsa:tst:1783343295002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-37.el9" test_ref="oval:com.tuxcare.clsa:tst:1783343295003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-37.el9" test_ref="oval:com.tuxcare.clsa:tst:1783343295004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-37.el9" test_ref="oval:com.tuxcare.clsa:tst:1783343295005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-37.el9" test_ref="oval:com.tuxcare.clsa:tst:1783343295006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-37.el9" test_ref="oval:com.tuxcare.clsa:tst:1783343295007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784298097" version="1">
      <metadata>
        <title>alt-python38: Fix of 35 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784298097" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784298097" source="CLSA"/>
        <reference ref_id="CVE-2025-13836" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13836" source="CVE"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2025-4516" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" source="CVE"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <reference ref_id="CVE-2025-4435" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" source="CVE"/>
        <reference ref_id="CVE-2025-15282" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" source="CVE"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2024-12718" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" source="CVE"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-12084" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <reference ref_id="CVE-2025-4138" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2025-13837" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" source="CVE"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <reference ref_id="CVE-2025-4330" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" source="CVE"/>
        <reference ref_id="CVE-2024-9287" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-9287" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2024-11168" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" source="CVE"/>
        <reference ref_id="CVE-2026-8328" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" source="CVE"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <reference ref_id="CVE-2026-0865" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" source="CVE"/>
        <reference ref_id="CVE-2025-4517" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <reference ref_id="CVE-2025-8291" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" source="CVE"/>
        <reference ref_id="CVE-2025-6069" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" source="CVE"/>
        <reference ref_id="CVE-2025-1795" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" source="CVE"/>
        <reference ref_id="CVE-2025-0938" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <reference ref_id="CVE-2025-11468" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" source="CVE"/>
        <description>- ELS-2237: apply 06004 (skip test_simple_xml_chunk_1/_5) on el7 too, not
  just rhel &gt;= 8. el7's expat now carries the 2.6 reparse-deferral backport
  while still reporting an older version, so those version-gated tests fail
  in %check as they already did on el8/el9.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-17"/>
          <updated date="2026-07-17"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13836" impact="important" public="20251201">CVE-2025-13836</cve>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-416" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4516" impact="moderate" public="20250515">CVE-2025-4516</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-706" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4435" impact="important" public="20250603">CVE-2025-4435</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" impact="moderate" public="20260120">CVE-2025-15282</cve>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve cvss3="7.6000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-12718" impact="important" public="20250603">CVE-2024-12718</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" impact="moderate" public="20251203">CVE-2025-12084</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4138" impact="important" public="20250603">CVE-2025-4138</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="important" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" impact="moderate" public="20251201">CVE-2025-13837</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4330" impact="important" public="20250603">CVE-2025-4330</cve>
          <cve cvss3="7.8/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-428" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-9287" impact="important" public="20241022">CVE-2024-9287</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-1287" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-11168" impact="moderate" public="20241112">CVE-2024-11168</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" impact="unknown" public="20260513">CVE-2026-8328</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" impact="moderate" public="20260120">CVE-2026-0865</cve>
          <cve cvss3="9.4/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517" impact="critical" public="20250603">CVE-2025-4517</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="important" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-130" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" impact="moderate" public="20251007">CVE-2025-8291</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" impact="moderate" public="20250617">CVE-2025-6069</cve>
          <cve cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-168" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" impact="low" public="20250228">CVE-2025-1795</cve>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-0938" impact="moderate" public="20250131">CVE-2025-0938</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="important" public="20260511">CVE-2026-7210</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-140" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" impact="moderate" public="20260120">CVE-2025-11468</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python38 is earlier than 0:3.8.20-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1784298097001"/>
        <criterion comment="alt-python38 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097002"/>
        <criterion comment="alt-python38-devel is earlier than 0:3.8.20-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1784298097003"/>
        <criterion comment="alt-python38-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097004"/>
        <criterion comment="alt-python38-idle is earlier than 0:3.8.20-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1784298097005"/>
        <criterion comment="alt-python38-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097006"/>
        <criterion comment="alt-python38-libs is earlier than 0:3.8.20-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1784298097007"/>
        <criterion comment="alt-python38-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097008"/>
        <criterion comment="alt-python38-test is earlier than 0:3.8.20-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1784298097009"/>
        <criterion comment="alt-python38-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097010"/>
        <criterion comment="alt-python38-tkinter is earlier than 0:3.8.20-19.el9" test_ref="oval:com.tuxcare.clsa:tst:1784298097011"/>
        <criterion comment="alt-python38-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097012"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784300728" version="1">
      <metadata>
        <title>alt-python39: Fix of 24 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784300728" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784300728" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2025-8194" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" source="CVE"/>
        <reference ref_id="CVE-2025-15282" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" source="CVE"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-12084" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <reference ref_id="CVE-2026-1299" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2025-13837" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" source="CVE"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <reference ref_id="CVE-2026-0865" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-0672" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" source="CVE"/>
        <reference ref_id="CVE-2025-8291" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" source="CVE"/>
        <reference ref_id="CVE-2025-6069" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" source="CVE"/>
        <reference ref_id="CVE-2025-1795" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <reference ref_id="CVE-2025-6075" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" source="CVE"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <reference ref_id="CVE-2025-11468" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" source="CVE"/>
        <description>- CVE-2026-9669: bz2.BZ2Decompressor records the libbz2 error code after a
  decompression failure and refuses any subsequent decompress() call with
  ValueError, instead of re-entering BZ2_bzDecompress() on an inconsistent
  bz_stream which could cause a stack buffer overflow (CWE-121).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-17"/>
          <updated date="2026-07-17"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-835" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8194" impact="important" public="20250728">CVE-2025-8194</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15282" impact="moderate" public="20260120">CVE-2025-15282</cve>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12084" impact="moderate" public="20251203">CVE-2025-12084</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1299" impact="important" public="20260123">CVE-2026-1299</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="important" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13837" impact="moderate" public="20251201">CVE-2025-13837</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
          <cve cvss3="5.9/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0865" impact="moderate" public="20260120">CVE-2026-0865</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="important" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0672" impact="moderate" public="20260120">CVE-2026-0672</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-130" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8291" impact="moderate" public="20251007">CVE-2025-8291</cve>
          <cve cvss3="4.3/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6069" impact="moderate" public="20250617">CVE-2025-6069</cve>
          <cve cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-168" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" impact="low" public="20250228">CVE-2025-1795</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <cve cvss3="5.5/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-6075" impact="moderate" public="20251031">CVE-2025-6075</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="important" public="20260511">CVE-2026-7210</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-140" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-11468" impact="moderate" public="20260120">CVE-2025-11468</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python39 is earlier than 0:3.9.23-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1784300728001"/>
        <criterion comment="alt-python39 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728002"/>
        <criterion comment="alt-python39-debug is earlier than 0:3.9.23-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1784300728003"/>
        <criterion comment="alt-python39-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728004"/>
        <criterion comment="alt-python39-devel is earlier than 0:3.9.23-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1784300728005"/>
        <criterion comment="alt-python39-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728006"/>
        <criterion comment="alt-python39-idle is earlier than 0:3.9.23-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1784300728007"/>
        <criterion comment="alt-python39-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728008"/>
        <criterion comment="alt-python39-libs is earlier than 0:3.9.23-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1784300728009"/>
        <criterion comment="alt-python39-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728010"/>
        <criterion comment="alt-python39-test is earlier than 0:3.9.23-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1784300728011"/>
        <criterion comment="alt-python39-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728012"/>
        <criterion comment="alt-python39-tkinter is earlier than 0:3.9.23-17.el9" test_ref="oval:com.tuxcare.clsa:tst:1784300728013"/>
        <criterion comment="alt-python39-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784311073" version="1">
      <metadata>
        <title>alt-python311: Fix of CVE-2024-6923</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784311073" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784311073" source="CLSA"/>
        <reference ref_id="CVE-2024-6923" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" source="CVE"/>
        <description>- ALTPYTH-591: Update to 3.11.15 version</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-17"/>
          <updated date="2026-07-17"/>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" impact="moderate" public="20240801">CVE-2024-6923</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311 is earlier than 0:3.11.15-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784311073001"/>
        <criterion comment="alt-python311 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073002"/>
        <criterion comment="alt-python311-debug is earlier than 0:3.11.15-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784311073003"/>
        <criterion comment="alt-python311-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073004"/>
        <criterion comment="alt-python311-devel is earlier than 0:3.11.15-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784311073005"/>
        <criterion comment="alt-python311-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073006"/>
        <criterion comment="alt-python311-idle is earlier than 0:3.11.15-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784311073007"/>
        <criterion comment="alt-python311-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073008"/>
        <criterion comment="alt-python311-libs is earlier than 0:3.11.15-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784311073009"/>
        <criterion comment="alt-python311-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073010"/>
        <criterion comment="alt-python311-test is earlier than 0:3.11.15-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784311073011"/>
        <criterion comment="alt-python311-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073012"/>
        <criterion comment="alt-python311-tkinter is earlier than 0:3.11.15-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784311073013"/>
        <criterion comment="alt-python311-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784312324" version="1">
      <metadata>
        <title>alt-python310: Fix of CVE-2024-6923</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784312324" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784312324" source="CLSA"/>
        <reference ref_id="CVE-2024-6923" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" source="CVE"/>
        <description>- ALTPYTH-592: Update to 3.10.20 version</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-17"/>
          <updated date="2026-07-17"/>
          <cve cvss3="6.8/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6923" impact="moderate" public="20240801">CVE-2024-6923</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784312324001"/>
        <criterion comment="alt-python310 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324002"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784312324003"/>
        <criterion comment="alt-python310-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324004"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784312324005"/>
        <criterion comment="alt-python310-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324006"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784312324007"/>
        <criterion comment="alt-python310-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324008"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784312324009"/>
        <criterion comment="alt-python310-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324010"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784312324011"/>
        <criterion comment="alt-python310-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324012"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-1.el9" test_ref="oval:com.tuxcare.clsa:tst:1784312324013"/>
        <criterion comment="alt-python310-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784372957" version="1">
      <metadata>
        <title>alt-python38-setuptools: Fix of 3 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784372957" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784372957" source="CLSA"/>
        <reference ref_id="CVE-2025-47273" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" source="CVE"/>
        <reference ref_id="CVE-2022-40897" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" source="CVE"/>
        <reference ref_id="CVE-2024-6345" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" source="CVE"/>
        <description>- CVE-2022-40897: regex denial of service via crafted HTML in package_index
- CVE-2024-6345: remote code execution via command injection in VCS download functions
- CVE-2025-47273: path traversal in PackageIndex download filename resolution</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-18"/>
          <updated date="2026-07-18"/>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" impact="important" public="20250517">CVE-2025-47273</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" impact="unknown" public="20221223">CVE-2022-40897</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" impact="important" public="20240715">CVE-2024-6345</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python38-setuptools is earlier than 0:58.3.0-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784372957001"/>
        <criterion comment="alt-python38-setuptools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784372957002"/>
        <criterion comment="alt-python38-setuptools-wheel is earlier than 0:58.3.0-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784372957003"/>
        <criterion comment="alt-python38-setuptools-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784372957004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784800604" version="1">
      <metadata>
        <title>alt-python310: Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784800604" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784800604" source="CLSA"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <description>- CVE-2025-15366: reject control characters in imaplib IMAP4 commands
- CVE-2025-15367: reject control characters in poplib POP3 commands
- CVE-2026-3644: reject control characters in http.cookies Morsel.update(), |=, unpickling and js_output
- CVE-2026-4224: add recursion guard to pyexpat conv_content_model() to prevent C stack overflow
- CVE-2026-4519: reject webbrowser URLs with a leading dash to prevent argument injection</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="important" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="important" public="20260316">CVE-2026-4224</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1784800604001"/>
        <criterion comment="alt-python310 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324002"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1784800604002"/>
        <criterion comment="alt-python310-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324004"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1784800604003"/>
        <criterion comment="alt-python310-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324006"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1784800604004"/>
        <criterion comment="alt-python310-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324008"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1784800604005"/>
        <criterion comment="alt-python310-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324010"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1784800604006"/>
        <criterion comment="alt-python310-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324012"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1784800604007"/>
        <criterion comment="alt-python310-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784804478" version="1">
      <metadata>
        <title>alt-python27: Fix of CVE-2026-15308</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784804478" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784804478" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>- CVE-2026-15308: fix quadratic-complexity CPU denial-of-service in incremental
  HTML parsing (Lib/HTMLParser.py). feed() previously concatenated new data onto
  the unparsed buffer and re-scanned it from the start on every call, so feeding
  an unterminated construct in many small chunks was quadratic. New data is now
  accumulated in a list and only joined and parsed once enough has piled up, with
  close() flushing the pending buffer. Port of gh-153030 (GH-153031).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-38.el9" test_ref="oval:com.tuxcare.clsa:tst:1784804478001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-38.el9" test_ref="oval:com.tuxcare.clsa:tst:1784804478002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-38.el9" test_ref="oval:com.tuxcare.clsa:tst:1784804478003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-38.el9" test_ref="oval:com.tuxcare.clsa:tst:1784804478004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-38.el9" test_ref="oval:com.tuxcare.clsa:tst:1784804478005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-38.el9" test_ref="oval:com.tuxcare.clsa:tst:1784804478006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-38.el9" test_ref="oval:com.tuxcare.clsa:tst:1784804478007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784811769" version="1">
      <metadata>
        <title>alt-python39: Fix of CVE-2026-15308</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784811769" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784811769" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>- el9: apply 06003 (BIO_eof ASN1 EOF, CPython gh-100372) so test_ssl
  test_load_verify_cadata / test_connect_cadata pass on OpenSSL &gt;= 3.5
  (el9 now ships openssl-libs 3.5.5, whose NOT_ENOUGH_DATA EOF reason code
  broke _add_ca_certs); the patch was previously gated to el10 only, which
  left the CL9 %check failing</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python39 is earlier than 0:3.9.23-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1784811769001"/>
        <criterion comment="alt-python39 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728002"/>
        <criterion comment="alt-python39-debug is earlier than 0:3.9.23-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1784811769002"/>
        <criterion comment="alt-python39-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728004"/>
        <criterion comment="alt-python39-devel is earlier than 0:3.9.23-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1784811769003"/>
        <criterion comment="alt-python39-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728006"/>
        <criterion comment="alt-python39-idle is earlier than 0:3.9.23-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1784811769004"/>
        <criterion comment="alt-python39-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728008"/>
        <criterion comment="alt-python39-libs is earlier than 0:3.9.23-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1784811769005"/>
        <criterion comment="alt-python39-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728010"/>
        <criterion comment="alt-python39-test is earlier than 0:3.9.23-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1784811769006"/>
        <criterion comment="alt-python39-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728012"/>
        <criterion comment="alt-python39-tkinter is earlier than 0:3.9.23-20.el9" test_ref="oval:com.tuxcare.clsa:tst:1784811769007"/>
        <criterion comment="alt-python39-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784815391" version="1">
      <metadata>
        <title>alt-python38: Fix of CVE-2026-15308</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784815391" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784815391" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>- el9: apply 06005 (BIO_eof ASN1 EOF, CPython gh-100372) so test_ssl
  test_load_verify_cadata / test_connect_cadata pass on OpenSSL &gt;= 3.5
  (el9 now ships openssl-libs 3.5.5, whose NOT_ENOUGH_DATA EOF reason code
  broke _add_ca_certs); the patch was not wired into the RPM spec before, so
  the CL9 %check failed</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python38 is earlier than 0:3.8.20-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1784815391001"/>
        <criterion comment="alt-python38 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097002"/>
        <criterion comment="alt-python38-devel is earlier than 0:3.8.20-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1784815391002"/>
        <criterion comment="alt-python38-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097004"/>
        <criterion comment="alt-python38-idle is earlier than 0:3.8.20-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1784815391003"/>
        <criterion comment="alt-python38-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097006"/>
        <criterion comment="alt-python38-libs is earlier than 0:3.8.20-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1784815391004"/>
        <criterion comment="alt-python38-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097008"/>
        <criterion comment="alt-python38-test is earlier than 0:3.8.20-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1784815391005"/>
        <criterion comment="alt-python38-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097010"/>
        <criterion comment="alt-python38-tkinter is earlier than 0:3.8.20-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1784815391006"/>
        <criterion comment="alt-python38-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097012"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784822014" version="1">
      <metadata>
        <title>alt-python36: Fix of CVE-2026-15308</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784822014" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784822014" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>- CVE-2026-15308: html.parser.HTMLParser had quadratic complexity when an
  unterminated construct (tag, comment, declaration) was fed across many
  feed() calls, since each call rescanned the growing buffer and
  reconcatenated onto it, allowing a CPU denial-of-service on uncontrolled
  data. feed() now accumulates new data in a list and only joins and parses
  it once enough has piled up, flushing the buffer in close() (upstream
  gh-153030 / bcf98ddb, adapted to 3.6: identical feed()/close()/reset()
  logic, test added with "from test import support", NEWS.d fragment omitted).</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1784822014001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1784822014002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1784822014003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1784822014004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1784822014005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1784822014006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-31.el9" test_ref="oval:com.tuxcare.clsa:tst:1784822014007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784823685" version="1">
      <metadata>
        <title>alt-python311: Fix of 9 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784823685" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784823685" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2025-15366" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" source="CVE"/>
        <reference ref_id="CVE-2025-15367" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" source="CVE"/>
        <reference ref_id="CVE-2026-3644" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" source="CVE"/>
        <reference ref_id="CVE-2026-4519" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2026-4786" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" source="CVE"/>
        <reference ref_id="CVE-2026-4224" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" source="CVE"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>- CVE-2026-4786: reject action-token-expanded dash-prefixed args in webbrowser.open() (CVE-2026-4519 bypass)
- CVE-2026-6100: fix dangling next_in pointer (UAF) in bz2/lzma decompressors after MemoryError on reuse
- CVE-2026-7210: use XML_SetHashSalt16Bytes 16-byte entropy for Expat hash-flooding protection when available
- CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (ubuntu16.04 / el7; other platforms link system expat) so the CVE-2026-7210 16-byte salt path is not inert
- CVE-2026-9669: prevent bz2.BZ2Decompressor reuse after a decompression error (stack buffer overflow)</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-23"/>
          <updated date="2026-07-23"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15366" impact="important" public="20260120">CVE-2025-15366</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-15367" impact="important" public="20260120">CVE-2025-15367</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3644" impact="important" public="20260316">CVE-2026-3644</cve>
          <cve cvss3="7.0/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4519" impact="important" public="20260320">CVE-2026-4519</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-88" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" impact="important" public="20260413">CVE-2026-4786</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-674" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4224" impact="important" public="20260316">CVE-2026-4224</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="important" public="20260511">CVE-2026-7210</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311 is earlier than 0:3.11.15-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784823685001"/>
        <criterion comment="alt-python311 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073002"/>
        <criterion comment="alt-python311-debug is earlier than 0:3.11.15-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784823685002"/>
        <criterion comment="alt-python311-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073004"/>
        <criterion comment="alt-python311-devel is earlier than 0:3.11.15-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784823685003"/>
        <criterion comment="alt-python311-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073006"/>
        <criterion comment="alt-python311-idle is earlier than 0:3.11.15-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784823685004"/>
        <criterion comment="alt-python311-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073008"/>
        <criterion comment="alt-python311-libs is earlier than 0:3.11.15-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784823685005"/>
        <criterion comment="alt-python311-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073010"/>
        <criterion comment="alt-python311-test is earlier than 0:3.11.15-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784823685006"/>
        <criterion comment="alt-python311-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073012"/>
        <criterion comment="alt-python311-tkinter is earlier than 0:3.11.15-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784823685007"/>
        <criterion comment="alt-python311-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784882920" version="1">
      <metadata>
        <title>alt-python310: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784882920" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784882920" source="CLSA"/>
        <reference ref_id="CVE-2026-6100" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" source="CVE"/>
        <reference ref_id="CVE-2026-9669" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" source="CVE"/>
        <reference ref_id="CVE-2026-4786" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" source="CVE"/>
        <reference ref_id="CVE-2026-7210" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" source="CVE"/>
        <description>- CVE-2026-4786: fix action-substitution bypass of the CVE-2026-4519 webbrowser dash-prefix check
- CVE-2026-6100: clear decompressor next_in on the error path in bz2/lzma to prevent use-after-free
- CVE-2026-7210: use XML_SetHashSalt16Bytes for 16-byte Expat hash-flooding entropy
- CVE-2026-41080: backport libexpat XML_SetHashSalt16Bytes into the bundled expat (Debian/Ubuntu, el7) so the CVE-2026-7210 16-byte salt path is not inert
- CVE-2026-9669: refuse bz2 decompressor reuse after a previous error to prevent stack buffer overflow</description>
        <advisory from="packager@tuxcare.com">
          <severity>Critical</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-24"/>
          <updated date="2026-07-24"/>
          <cve cvss3="9.1/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-825" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100" impact="critical" public="20260413">CVE-2026-6100</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-9669" impact="unknown" public="20260608">CVE-2026-9669</cve>
          <cve cvss3="7.1000000000000005/CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L" cwe="CWE-88" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4786" impact="important" public="20260413">CVE-2026-4786</cve>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-331" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7210" impact="important" public="20260511">CVE-2026-7210</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784882920001"/>
        <criterion comment="alt-python310 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324002"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784882920002"/>
        <criterion comment="alt-python310-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324004"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784882920003"/>
        <criterion comment="alt-python310-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324006"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784882920004"/>
        <criterion comment="alt-python310-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324008"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784882920005"/>
        <criterion comment="alt-python310-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324010"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784882920006"/>
        <criterion comment="alt-python310-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324012"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1784882920007"/>
        <criterion comment="alt-python310-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1784902318" version="1">
      <metadata>
        <title>alt-python310: Fix of CVE-2026-15308</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1784902318" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1784902318" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>- CVE-2026-15308: fix quadratic-complexity CPU DoS in html.parser.HTMLParser incremental parsing of long unterminated constructs</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-24"/>
          <updated date="2026-07-24"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1784902318001"/>
        <criterion comment="alt-python310 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324002"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1784902318002"/>
        <criterion comment="alt-python310-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324004"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1784902318003"/>
        <criterion comment="alt-python310-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324006"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1784902318004"/>
        <criterion comment="alt-python310-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324008"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1784902318005"/>
        <criterion comment="alt-python310-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324010"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1784902318006"/>
        <criterion comment="alt-python310-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324012"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1784902318007"/>
        <criterion comment="alt-python310-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785141727" version="1">
      <metadata>
        <title>alt-python311: Fix of CVE-2026-15308</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785141727" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785141727" source="CLSA"/>
        <reference ref_id="CVE-2026-15308" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" source="CVE"/>
        <description>- CVE-2026-15308: fix quadratic complexity in html.parser.HTMLParser incremental parsing of long unterminated markup declarations (CPU denial-of-service)</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-27"/>
          <updated date="2026-07-27"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-400" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-15308" impact="important" public="20260709">CVE-2026-15308</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311 is earlier than 0:3.11.15-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785141727001"/>
        <criterion comment="alt-python311 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073002"/>
        <criterion comment="alt-python311-debug is earlier than 0:3.11.15-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785141727002"/>
        <criterion comment="alt-python311-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073004"/>
        <criterion comment="alt-python311-devel is earlier than 0:3.11.15-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785141727003"/>
        <criterion comment="alt-python311-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073006"/>
        <criterion comment="alt-python311-idle is earlier than 0:3.11.15-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785141727004"/>
        <criterion comment="alt-python311-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073008"/>
        <criterion comment="alt-python311-libs is earlier than 0:3.11.15-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785141727005"/>
        <criterion comment="alt-python311-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073010"/>
        <criterion comment="alt-python311-test is earlier than 0:3.11.15-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785141727006"/>
        <criterion comment="alt-python311-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073012"/>
        <criterion comment="alt-python311-tkinter is earlier than 0:3.11.15-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785141727007"/>
        <criterion comment="alt-python311-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785148862" version="1">
      <metadata>
        <title>alt-python36-setuptools: Fix of 3 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785148862" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785148862" source="CLSA"/>
        <reference ref_id="CVE-2025-47273" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" source="CVE"/>
        <reference ref_id="CVE-2022-40897" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" source="CVE"/>
        <reference ref_id="CVE-2024-6345" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" source="CVE"/>
        <description>- CVE-2022-40897: regex denial of service via crafted HTML in package_index
- CVE-2024-6345: remote code execution via command injection in VCS download functions
- CVE-2025-47273: path traversal in PackageIndex download filename resolution</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-27"/>
          <updated date="2026-07-27"/>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" impact="important" public="20250517">CVE-2025-47273</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" impact="unknown" public="20221223">CVE-2022-40897</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" impact="important" public="20240715">CVE-2024-6345</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36-setuptools is earlier than 0:38.5.2-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785148862001"/>
        <criterion comment="alt-python36-setuptools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785148862002"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785171014" version="1">
      <metadata>
        <title>alt-python310-pip: Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785171014" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785171014" source="CLSA"/>
        <reference ref_id="CVE-2026-1703" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" source="CVE"/>
        <reference ref_id="CVE-2025-8869" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" source="CVE"/>
        <reference ref_id="CVE-2023-5752" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" source="CVE"/>
        <reference ref_id="CVE-2026-3219" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" source="CVE"/>
        <reference ref_id="CVE-2026-6357" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" source="CVE"/>
        <description>- CVE-2023-5752: Mercurial revision option injection in pip VCS URLs
- CVE-2025-8869: symlink target not validated in tar extraction fallback
- CVE-2026-1703: path traversal via os.path.commonprefix in is_within_directory
- CVE-2026-3219: tar/ZIP polyglot archive type confusion in unpack_file
- CVE-2026-6357: pip self-version check runs after install allowing module shadowing</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-27"/>
          <updated date="2026-07-27"/>
          <cve cvss3="3.9/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" impact="low" public="20260202">CVE-2026-1703</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" impact="unknown">CVE-2025-8869</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" impact="unknown" public="20231025">CVE-2023-5752</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" impact="unknown">CVE-2026-3219</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" impact="unknown">CVE-2026-6357</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310-pip is earlier than 0:21.3.1-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785171014001"/>
        <criterion comment="alt-python310-pip isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785171014002"/>
        <criterion comment="alt-python310-pip-wheel is earlier than 0:21.3.1-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785171014003"/>
        <criterion comment="alt-python310-pip-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785171014004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785171898" version="1">
      <metadata>
        <title>alt-python311-pip: Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785171898" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785171898" source="CLSA"/>
        <reference ref_id="CVE-2026-1703" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" source="CVE"/>
        <reference ref_id="CVE-2025-8869" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" source="CVE"/>
        <reference ref_id="CVE-2023-5752" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" source="CVE"/>
        <reference ref_id="CVE-2026-3219" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" source="CVE"/>
        <reference ref_id="CVE-2026-6357" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" source="CVE"/>
        <description>- CVE-2023-5752: Mercurial option injection via crafted VCS revision
- CVE-2025-8869: arbitrary file overwrite via symlinks in sdist tarballs
- CVE-2026-3219: archive confusion via tar/ZIP polyglot files
- CVE-2026-1703: path traversal via string-prefix sibling directories
- CVE-2026-6357: code execution via post-install pip self-version check imports</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-27"/>
          <updated date="2026-07-27"/>
          <cve cvss3="3.9/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" impact="low" public="20260202">CVE-2026-1703</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" impact="unknown">CVE-2025-8869</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" impact="unknown" public="20231025">CVE-2023-5752</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" impact="unknown">CVE-2026-3219</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" impact="unknown">CVE-2026-6357</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311-pip is earlier than 0:21.3.1-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785171898001"/>
        <criterion comment="alt-python311-pip isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785171898002"/>
        <criterion comment="alt-python311-pip-wheel is earlier than 0:21.3.1-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785171898003"/>
        <criterion comment="alt-python311-pip-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785171898004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785173409" version="1">
      <metadata>
        <title>alt-python38-pip: Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785173409" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785173409" source="CLSA"/>
        <reference ref_id="CVE-2026-1703" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" source="CVE"/>
        <reference ref_id="CVE-2025-8869" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" source="CVE"/>
        <reference ref_id="CVE-2023-5752" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" source="CVE"/>
        <reference ref_id="CVE-2026-3219" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" source="CVE"/>
        <reference ref_id="CVE-2026-6357" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" source="CVE"/>
        <description>- CVE-2023-5752: Mercurial configuration injection via VCS URL revision option
- CVE-2025-8869: symlink targets not validated in fallback tar extraction
- CVE-2026-1703: path traversal via prefix matching when extracting archives
- CVE-2026-3219: concatenated tar/ZIP archives misinterpreted as ZIP
- CVE-2026-6357: self-version check could import modules from newly installed wheels</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-27"/>
          <updated date="2026-07-27"/>
          <cve cvss3="3.9/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" impact="low" public="20260202">CVE-2026-1703</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" impact="unknown">CVE-2025-8869</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" impact="unknown" public="20231025">CVE-2023-5752</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" impact="unknown">CVE-2026-3219</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" impact="unknown">CVE-2026-6357</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python38-pip is earlier than 0:22.2.1-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785173409001"/>
        <criterion comment="alt-python38-pip isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785173409002"/>
        <criterion comment="alt-python38-pip-wheel is earlier than 0:22.2.1-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785173409003"/>
        <criterion comment="alt-python38-pip-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785173409004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785228248" version="1">
      <metadata>
        <title>alt-python38-wheel: Fix of CVE-2022-40898</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785228248" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785228248" source="CLSA"/>
        <reference ref_id="CVE-2022-40898" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" source="CVE"/>
        <description>- CVE-2022-40898: regex denial of service via crafted wheel filename in WHEEL_INFO_RE</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-28"/>
          <updated date="2026-07-28"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" impact="important" public="20221223">CVE-2022-40898</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python38-wheel is earlier than 1:0.37.1-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1785228248001"/>
        <criterion comment="alt-python38-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785228248002"/>
        <criterion comment="alt-python38-wheel-wheel is earlier than 1:0.37.1-3.el9" test_ref="oval:com.tuxcare.clsa:tst:1785228248003"/>
        <criterion comment="alt-python38-wheel-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785228248004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785230640" version="1">
      <metadata>
        <title>alt-python39-setuptools: Fix of 3 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785230640" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785230640" source="CLSA"/>
        <reference ref_id="CVE-2025-47273" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" source="CVE"/>
        <reference ref_id="CVE-2022-40897" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" source="CVE"/>
        <reference ref_id="CVE-2024-6345" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" source="CVE"/>
        <description>- CVE-2022-40897: regex denial of service via crafted HTML in package_index
- CVE-2024-6345: remote code execution via command injection in VCS download functions
- CVE-2025-47273: path traversal in PackageIndex download filename resolution
- Fix el7 build so the CVE fixes above can ship there: rpm 4.11 strips
  backslashes in shell-expansion macro bodies, so the sed capture
  group in the os_install_post override never matched and python3.9
  modules were bytecompiled with the system python2, failing the
  install step on python3-only syntax; rewrite the sed without a
  group and stop relying on the interpreter-path macro from
  alt-python39-devel, whose macros file lives in /usr/lib/rpm/macros.d
  that rpm 4.11 does not read</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-28"/>
          <updated date="2026-07-28"/>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" impact="important" public="20250517">CVE-2025-47273</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" impact="unknown" public="20221223">CVE-2022-40897</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" impact="important" public="20240715">CVE-2024-6345</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python39-setuptools is earlier than 0:58.3.0-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785230640001"/>
        <criterion comment="alt-python39-setuptools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785230640002"/>
        <criterion comment="alt-python39-setuptools-wheel is earlier than 0:58.3.0-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785230640003"/>
        <criterion comment="alt-python39-setuptools-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785230640004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785237053" version="1">
      <metadata>
        <title>alt-python311-wheel: Fix of CVE-2022-40898</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785237053" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785237053" source="CLSA"/>
        <reference ref_id="CVE-2022-40898" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" source="CVE"/>
        <description>- CVE-2022-40898: denial of service via crafted input to wheel cli (ReDoS in WHEEL_INFO_RE)</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-28"/>
          <updated date="2026-07-28"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" impact="important" public="20221223">CVE-2022-40898</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311-wheel is earlier than 0:0.37.0-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1785237053001"/>
        <criterion comment="alt-python311-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785237053002"/>
        <criterion comment="alt-python311-wheel-wheel is earlier than 0:0.37.0-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1785237053003"/>
        <criterion comment="alt-python311-wheel-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785237053004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785241961" version="1">
      <metadata>
        <title>alt-python311-setuptools: Fix of 2 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785241961" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785241961" source="CLSA"/>
        <reference ref_id="CVE-2025-47273" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" source="CVE"/>
        <reference ref_id="CVE-2024-6345" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" source="CVE"/>
        <description>- CVE-2024-6345: remote code execution via command injection in VCS download functions
- CVE-2025-47273: path traversal in PackageIndex download filename resolution</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-28"/>
          <updated date="2026-07-28"/>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" impact="important" public="20250517">CVE-2025-47273</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" impact="important" public="20240715">CVE-2024-6345</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311-setuptools is earlier than 0:65.6.3-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785241961001"/>
        <criterion comment="alt-python311-setuptools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785241961002"/>
        <criterion comment="alt-python311-setuptools-wheel is earlier than 0:65.6.3-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785241961003"/>
        <criterion comment="alt-python311-setuptools-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785241961004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785310634" version="1">
      <metadata>
        <title>alt-python39-wheel: Fix of CVE-2022-40898</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785310634" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785310634" source="CLSA"/>
        <reference ref_id="CVE-2022-40898" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" source="CVE"/>
        <description>- CVE-2022-40898: regex denial of service via crafted wheel filename in WHEEL_INFO_RE</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-29"/>
          <updated date="2026-07-29"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" impact="important" public="20221223">CVE-2022-40898</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python39-wheel is earlier than 0:0.37.0-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785310634001"/>
        <criterion comment="alt-python39-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785310634002"/>
        <criterion comment="alt-python39-wheel-wheel is earlier than 0:0.37.0-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785310634003"/>
        <criterion comment="alt-python39-wheel-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785310634004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785315201" version="1">
      <metadata>
        <title>alt-python36-wheel: Fix of CVE-2022-40898</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785315201" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785315201" source="CLSA"/>
        <reference ref_id="CVE-2022-40898" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" source="CVE"/>
        <description>- CVE-2022-40898: redos in WHEEL_INFO_RE via wheel file names with many dashes;
  bound every lazy quantifier span with a character class.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-29"/>
          <updated date="2026-07-29"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" impact="important" public="20221223">CVE-2022-40898</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36-wheel is earlier than 0:0.31.1-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1785315201001"/>
        <criterion comment="alt-python36-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785315201002"/>
        <criterion comment="alt-python36-wheel-wheel is earlier than 0:0.31.1-2.el9" test_ref="oval:com.tuxcare.clsa:tst:1785315201003"/>
        <criterion comment="alt-python36-wheel-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785315201004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785325771" version="1">
      <metadata>
        <title>alt-python310-wheel: Fix of CVE-2022-40898</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785325771" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785325771" source="CLSA"/>
        <reference ref_id="CVE-2022-40898" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" source="CVE"/>
        <description>- CVE-2022-40898: denial of service via regular expression in WHEEL_INFO_RE</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-29"/>
          <updated date="2026-07-29"/>
          <cve cvss3="7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40898" impact="important" public="20221223">CVE-2022-40898</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310-wheel is earlier than 0:0.37.0-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785325771001"/>
        <criterion comment="alt-python310-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785325771002"/>
        <criterion comment="alt-python310-wheel-wheel is earlier than 0:0.37.0-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785325771003"/>
        <criterion comment="alt-python310-wheel-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785325771004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785330970" version="1">
      <metadata>
        <title>alt-python310-setuptools: Fix of 3 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785330970" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785330970" source="CLSA"/>
        <reference ref_id="CVE-2025-47273" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" source="CVE"/>
        <reference ref_id="CVE-2022-40897" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" source="CVE"/>
        <reference ref_id="CVE-2024-6345" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" source="CVE"/>
        <description>- CVE-2022-40897: regex denial of service via crafted HTML in package_index
- CVE-2024-6345: remote code execution via command injection in VCS download functions
- CVE-2025-47273: path traversal in PackageIndex download filename resolution</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-29"/>
          <updated date="2026-07-29"/>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-47273" impact="important" public="20250517">CVE-2025-47273</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" cwe="CWE-1333" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-40897" impact="unknown" public="20221223">CVE-2022-40897</cve>
          <cve cvss3="8.8/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" cwe="CWE-94" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2024-6345" impact="important" public="20240715">CVE-2024-6345</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310-setuptools is earlier than 0:58.3.0-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785330970001"/>
        <criterion comment="alt-python310-setuptools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785330970002"/>
        <criterion comment="alt-python310-setuptools-wheel is earlier than 0:58.3.0-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785330970003"/>
        <criterion comment="alt-python310-setuptools-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785330970004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785335543" version="1">
      <metadata>
        <title>alt-python39-pip: Fix of 5 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785335543" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785335543" source="CLSA"/>
        <reference ref_id="CVE-2026-1703" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" source="CVE"/>
        <reference ref_id="CVE-2025-8869" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" source="CVE"/>
        <reference ref_id="CVE-2023-5752" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" source="CVE"/>
        <reference ref_id="CVE-2026-3219" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" source="CVE"/>
        <reference ref_id="CVE-2026-6357" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" source="CVE"/>
        <description>- CVE-2023-5752: Mercurial revision option injection via VCS URL
- CVE-2025-8869: tar extraction misses symlink target check (no PEP 706 fallback)
- CVE-2026-1703: path traversal via os.path.commonprefix containment check
- CVE-2026-3219: tar/ZIP polyglot archive interpretation conflict
- CVE-2026-6357: post-install self-version check could import malicious wheel content
- Restore el7 byte-compile path (regression from 21.3.1-3): double the
  backslashes in the __os_install_post sed capture group so the rewrite
  to the alt-python interpreter survives rpm macro expansion on el7</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-29"/>
          <updated date="2026-07-29"/>
          <cve cvss3="3.9/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1703" impact="low" public="20260202">CVE-2026-1703</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-8869" impact="unknown">CVE-2025-8869</cve>
          <cve cvss3="0.0/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-77" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2023-5752" impact="unknown" public="20231025">CVE-2023-5752</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3219" impact="unknown">CVE-2026-3219</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6357" impact="unknown">CVE-2026-6357</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python39-pip is earlier than 0:21.3.1-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785335543001"/>
        <criterion comment="alt-python39-pip isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785335543002"/>
        <criterion comment="alt-python39-pip-wheel is earlier than 0:21.3.1-4.el9" test_ref="oval:com.tuxcare.clsa:tst:1785335543003"/>
        <criterion comment="alt-python39-pip-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785335543004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785342083" version="1">
      <metadata>
        <title>alt-python311: Fix of 8 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785342083" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785342083" source="CLSA"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2026-0864" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" source="CVE"/>
        <reference ref_id="CVE-2026-11972" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" source="CVE"/>
        <reference ref_id="CVE-2026-3276" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" source="CVE"/>
        <reference ref_id="CVE-2026-8328" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" source="CVE"/>
        <reference ref_id="CVE-2026-11940" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <reference ref_id="CVE-2026-7774" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" source="CVE"/>
        <description>- CVE-2026-0864: normalize CR/CRLF line endings in configparser writes to prevent key/value injection
- CVE-2026-1502: reject CR/LF in http.client proxy CONNECT tunnel host and headers
- CVE-2026-3276: fix O(n^2) canonical ordering in unicodedata.normalize() (DoS on crafted combining sequences)
- CVE-2026-6019: percent-encode cookie values embedded in http.cookies js_output() to prevent script injection (XSS)
- CVE-2026-7774: validate written link target in tarfile data filter to prevent path traversal
- CVE-2026-8328: apply CVE-2021-4189 PASV peer-address check to ftplib.ftpcp() to prevent data-connection SSRF
- CVE-2026-11940: fix symlink escape via tarfile hardlink-extraction fallback (path traversal)
- CVE-2026-11972: make tarfile._Stream.seek() break at EOF to prevent infinite-loop DoS on crafted stream archives</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-29"/>
          <updated date="2026-07-29"/>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" impact="unknown" public="20260623">CVE-2026-0864</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" impact="unknown" public="20260623">CVE-2026-11972</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" impact="unknown" public="20260603">CVE-2026-3276</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" impact="unknown" public="20260513">CVE-2026-8328</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" impact="unknown" public="20260623">CVE-2026-11940</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" impact="unknown" public="20260604">CVE-2026-7774</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311 is earlier than 0:3.11.15-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785342083001"/>
        <criterion comment="alt-python311 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073002"/>
        <criterion comment="alt-python311-debug is earlier than 0:3.11.15-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785342083002"/>
        <criterion comment="alt-python311-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073004"/>
        <criterion comment="alt-python311-devel is earlier than 0:3.11.15-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785342083003"/>
        <criterion comment="alt-python311-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073006"/>
        <criterion comment="alt-python311-idle is earlier than 0:3.11.15-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785342083004"/>
        <criterion comment="alt-python311-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073008"/>
        <criterion comment="alt-python311-libs is earlier than 0:3.11.15-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785342083005"/>
        <criterion comment="alt-python311-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073010"/>
        <criterion comment="alt-python311-test is earlier than 0:3.11.15-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785342083006"/>
        <criterion comment="alt-python311-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073012"/>
        <criterion comment="alt-python311-tkinter is earlier than 0:3.11.15-5.el9" test_ref="oval:com.tuxcare.clsa:tst:1785342083007"/>
        <criterion comment="alt-python311-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785403906" version="1">
      <metadata>
        <title>alt-python39: Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785403906" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785403906" source="CLSA"/>
        <reference ref_id="CVE-2026-4360" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4360" source="CVE"/>
        <reference ref_id="CVE-2026-0864" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" source="CVE"/>
        <reference ref_id="CVE-2026-11972" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" source="CVE"/>
        <reference ref_id="CVE-2026-3276" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" source="CVE"/>
        <reference ref_id="CVE-2026-8328" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" source="CVE"/>
        <reference ref_id="CVE-2026-11940" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" source="CVE"/>
        <reference ref_id="CVE-2026-7774" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" source="CVE"/>
        <description>- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to
  _extract_one(), so on the code path that extracts a hardlink the filter was
  silently dropped. An archive extracted with filter='data' could therefore
  create files with an attacker-chosen uid/gid instead of the filtered values
  (CWE-noinfo: incorrect enforcement of an extraction filter). Backport of
  cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to
  _extract_one().</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-30"/>
          <updated date="2026-07-30"/>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-281" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4360" impact="moderate" public="20260630">CVE-2026-4360</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" impact="unknown" public="20260623">CVE-2026-0864</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" impact="unknown" public="20260623">CVE-2026-11972</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" impact="unknown" public="20260603">CVE-2026-3276</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" impact="unknown" public="20260513">CVE-2026-8328</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" impact="unknown" public="20260623">CVE-2026-11940</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" impact="unknown" public="20260604">CVE-2026-7774</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python39 is earlier than 0:3.9.23-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1785403906001"/>
        <criterion comment="alt-python39 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728002"/>
        <criterion comment="alt-python39-debug is earlier than 0:3.9.23-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1785403906002"/>
        <criterion comment="alt-python39-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728004"/>
        <criterion comment="alt-python39-devel is earlier than 0:3.9.23-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1785403906003"/>
        <criterion comment="alt-python39-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728006"/>
        <criterion comment="alt-python39-idle is earlier than 0:3.9.23-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1785403906004"/>
        <criterion comment="alt-python39-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728008"/>
        <criterion comment="alt-python39-libs is earlier than 0:3.9.23-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1785403906005"/>
        <criterion comment="alt-python39-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728010"/>
        <criterion comment="alt-python39-test is earlier than 0:3.9.23-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1785403906006"/>
        <criterion comment="alt-python39-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728012"/>
        <criterion comment="alt-python39-tkinter is earlier than 0:3.9.23-24.el9" test_ref="oval:com.tuxcare.clsa:tst:1785403906007"/>
        <criterion comment="alt-python39-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785418319" version="1">
      <metadata>
        <title>alt-python36-pip: Fix of CVE-2021-3572</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785418319" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785418319" source="CLSA"/>
        <reference ref_id="CVE-2021-3572" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3572" source="CVE"/>
        <description>- CVE-2021-3572: Fix revision hijacking via unicode separators in git references</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-30"/>
          <updated date="2026-07-30"/>
          <cve cvss3="0.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3572" impact="unknown" public="20211110">CVE-2021-3572</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36-pip is earlier than 0:20.2.4-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785418319001"/>
        <criterion comment="alt-python36-pip isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785418319002"/>
        <criterion comment="alt-python36-pip-wheel is earlier than 0:20.2.4-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785418319003"/>
        <criterion comment="alt-python36-pip-wheel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785418319004"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785422123" version="1">
      <metadata>
        <title>alt-python39: Fix of CVE-2025-12781</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785422123" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785422123" source="CLSA"/>
        <reference ref_id="CVE-2025-12781" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12781" source="CVE"/>
        <description>- CVE-2025-12781: base64.b64decode() and urlsafe_b64decode() always
  accepted the standard-alphabet '+' and '/' characters even when an
  alternative alphabet excluding them was specified via altchars, so
  malformed input could bypass strict-alphabet validation filters
  (CWE-704: incorrect type conversion or cast, per NVD). Backport of cpython 9060b4ab
  (gh-125346, PR gh-141128): emits DeprecationWarning/FutureWarning
  when such characters are seen; decoded output is unchanged.</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-30"/>
          <updated date="2026-07-30"/>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-704" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12781" impact="moderate" public="20260121">CVE-2025-12781</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python39 is earlier than 0:3.9.23-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1785422123001"/>
        <criterion comment="alt-python39 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728002"/>
        <criterion comment="alt-python39-debug is earlier than 0:3.9.23-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1785422123002"/>
        <criterion comment="alt-python39-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728004"/>
        <criterion comment="alt-python39-devel is earlier than 0:3.9.23-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1785422123003"/>
        <criterion comment="alt-python39-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728006"/>
        <criterion comment="alt-python39-idle is earlier than 0:3.9.23-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1785422123004"/>
        <criterion comment="alt-python39-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728008"/>
        <criterion comment="alt-python39-libs is earlier than 0:3.9.23-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1785422123005"/>
        <criterion comment="alt-python39-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728010"/>
        <criterion comment="alt-python39-test is earlier than 0:3.9.23-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1785422123006"/>
        <criterion comment="alt-python39-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728012"/>
        <criterion comment="alt-python39-tkinter is earlier than 0:3.9.23-21.el9" test_ref="oval:com.tuxcare.clsa:tst:1785422123007"/>
        <criterion comment="alt-python39-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784300728014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785429417" version="1">
      <metadata>
        <title>alt-python310: Fix of 12 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785429417" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785429417" source="CLSA"/>
        <reference ref_id="CVE-2025-12781" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12781" source="CVE"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <reference ref_id="CVE-2026-1502" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" source="CVE"/>
        <reference ref_id="CVE-2026-0864" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" source="CVE"/>
        <reference ref_id="CVE-2026-11972" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" source="CVE"/>
        <reference ref_id="CVE-2026-3276" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" source="CVE"/>
        <reference ref_id="CVE-2026-8328" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" source="CVE"/>
        <reference ref_id="CVE-2026-3446" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" source="CVE"/>
        <reference ref_id="CVE-2026-11940" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" source="CVE"/>
        <reference ref_id="CVE-2025-1795" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" source="CVE"/>
        <reference ref_id="CVE-2026-6019" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" source="CVE"/>
        <reference ref_id="CVE-2026-7774" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" source="CVE"/>
        <description>- CVE-2026-3446: stop ignoring excess base64 data after the first padded quad in binascii.a2b_base64(), which backs base64.b64decode()
- CVE-2026-11940: revalidate the hardlink's own shallower path in the tarfile extraction fallback so a symlink cannot escape the destination directory, and pass the extraction filter from extract() down to _extract_one() so the revalidation runs for single-member extraction as well and not only for extractall()
- CVE-2026-6019: percent-encode the cookie value embedded in the http.cookies Morsel.js_output() script snippet and decode it with decodeURIComponent() to prevent breaking out of the script element while keeping UTF-8 values intact</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-30"/>
          <updated date="2026-07-30"/>
          <cve cvss3="6.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-704" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-12781" impact="moderate" public="20260121">CVE-2025-12781</cve>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <cve cvss3="5.7/CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" cwe="CWE-93" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-1502" impact="moderate" public="20260410">CVE-2026-1502</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" impact="unknown" public="20260623">CVE-2026-0864</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" impact="unknown" public="20260623">CVE-2026-11972</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" impact="unknown" public="20260603">CVE-2026-3276</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" impact="unknown" public="20260513">CVE-2026-8328</cve>
          <cve cvss3="6.0/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N" cwe="CWE-1286" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3446" impact="moderate" public="20260410">CVE-2026-3446</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" impact="unknown" public="20260623">CVE-2026-11940</cve>
          <cve cvss3="3.1/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" cwe="CWE-168" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-1795" impact="low" public="20250228">CVE-2025-1795</cve>
          <cve cvss3="6.1000000000000005/CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" cwe="CWE-150" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6019" impact="moderate" public="20260422">CVE-2026-6019</cve>
          <cve href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" impact="unknown" public="20260604">CVE-2026-7774</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python310 is earlier than 0:3.10.20-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785429417001"/>
        <criterion comment="alt-python310 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324002"/>
        <criterion comment="alt-python310-debug is earlier than 0:3.10.20-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785429417002"/>
        <criterion comment="alt-python310-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324004"/>
        <criterion comment="alt-python310-devel is earlier than 0:3.10.20-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785429417003"/>
        <criterion comment="alt-python310-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324006"/>
        <criterion comment="alt-python310-idle is earlier than 0:3.10.20-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785429417004"/>
        <criterion comment="alt-python310-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324008"/>
        <criterion comment="alt-python310-libs is earlier than 0:3.10.20-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785429417005"/>
        <criterion comment="alt-python310-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324010"/>
        <criterion comment="alt-python310-test is earlier than 0:3.10.20-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785429417006"/>
        <criterion comment="alt-python310-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324012"/>
        <criterion comment="alt-python310-tkinter is earlier than 0:3.10.20-9.el9" test_ref="oval:com.tuxcare.clsa:tst:1785429417007"/>
        <criterion comment="alt-python310-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784312324014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1785502244" version="1">
      <metadata>
        <title>alt-python311: Fix of CVE-2025-13462</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1785502244" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1785502244" source="CLSA"/>
        <reference ref_id="CVE-2025-13462" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" source="CVE"/>
        <description>- CVE-2025-13462: skip tarfile AREGTYPE-&gt;DIRTYPE normalization while parsing GNU long name/link continuation headers (parser-differential)</description>
        <advisory from="packager@tuxcare.com">
          <severity>Low</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-07-31"/>
          <updated date="2026-07-31"/>
          <cve cvss3="3.3000000000000003/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-20" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-13462" impact="low" public="20260312">CVE-2025-13462</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python311 is earlier than 0:3.11.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785502244001"/>
        <criterion comment="alt-python311 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073002"/>
        <criterion comment="alt-python311-debug is earlier than 0:3.11.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785502244002"/>
        <criterion comment="alt-python311-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073004"/>
        <criterion comment="alt-python311-devel is earlier than 0:3.11.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785502244003"/>
        <criterion comment="alt-python311-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073006"/>
        <criterion comment="alt-python311-idle is earlier than 0:3.11.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785502244004"/>
        <criterion comment="alt-python311-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073008"/>
        <criterion comment="alt-python311-libs is earlier than 0:3.11.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785502244005"/>
        <criterion comment="alt-python311-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073010"/>
        <criterion comment="alt-python311-test is earlier than 0:3.11.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785502244006"/>
        <criterion comment="alt-python311-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073012"/>
        <criterion comment="alt-python311-tkinter is earlier than 0:3.11.15-6.el9" test_ref="oval:com.tuxcare.clsa:tst:1785502244007"/>
        <criterion comment="alt-python311-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784311073014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1786468319" version="1">
      <metadata>
        <title>alt-python36-setuptools: Fix of CVE-2026-59890</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1786468319" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1786468319" source="CLSA"/>
        <reference ref_id="CVE-2026-59890" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-59890" source="CVE"/>
        <description>- CVE-2026-59890: MANIFEST.in exclusion bypass via Unicode normalization mismatch in FileList</description>
        <advisory from="packager@tuxcare.com">
          <severity>Moderate</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-11"/>
          <updated date="2026-08-11"/>
          <cve cwe="CWE-176" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-59890" impact="unknown" public="20260708">CVE-2026-59890</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36-setuptools is earlier than 0:38.5.2-10.el9" test_ref="oval:com.tuxcare.clsa:tst:1786468319001"/>
        <criterion comment="alt-python36-setuptools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1785148862002"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1786541588" version="1">
      <metadata>
        <title>alt-python27: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1786541588" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1786541588" source="CLSA"/>
        <reference ref_id="CVE-2026-0864" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" source="CVE"/>
        <reference ref_id="CVE-2026-11972" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" source="CVE"/>
        <reference ref_id="CVE-2026-3276" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" source="CVE"/>
        <reference ref_id="CVE-2026-8328" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" source="CVE"/>
        <description>- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
  ftpcp() as well; ftpcp() previously passed the raw attacker-controllable
  IPv4 address and port from the source server's PASV reply straight to
  target.sendport(), letting a malicious source server redirect the target
  server's data connection to an arbitrary host:port. ftpcp() now uses the
  source server's real peer address, honoring the existing
  trust_server_pasv_ipv4_address opt-out</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-12"/>
          <updated date="2026-08-12"/>
          <cve cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" impact="unknown" public="20260623">CVE-2026-0864</cve>
          <cve cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" impact="unknown" public="20260623">CVE-2026-11972</cve>
          <cve cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" impact="unknown" public="20260603">CVE-2026-3276</cve>
          <cve cwe="CWE-918" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" impact="unknown" public="20260513">CVE-2026-8328</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python27 is earlier than 0:2.7.18-41.el9" test_ref="oval:com.tuxcare.clsa:tst:1786541588001"/>
        <criterion comment="alt-python27 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881002"/>
        <criterion comment="alt-python27-debug is earlier than 0:2.7.18-41.el9" test_ref="oval:com.tuxcare.clsa:tst:1786541588002"/>
        <criterion comment="alt-python27-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881004"/>
        <criterion comment="alt-python27-devel is earlier than 0:2.7.18-41.el9" test_ref="oval:com.tuxcare.clsa:tst:1786541588003"/>
        <criterion comment="alt-python27-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881006"/>
        <criterion comment="alt-python27-libs is earlier than 0:2.7.18-41.el9" test_ref="oval:com.tuxcare.clsa:tst:1786541588004"/>
        <criterion comment="alt-python27-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881008"/>
        <criterion comment="alt-python27-test is earlier than 0:2.7.18-41.el9" test_ref="oval:com.tuxcare.clsa:tst:1786541588005"/>
        <criterion comment="alt-python27-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881010"/>
        <criterion comment="alt-python27-tkinter is earlier than 0:2.7.18-41.el9" test_ref="oval:com.tuxcare.clsa:tst:1786541588006"/>
        <criterion comment="alt-python27-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881012"/>
        <criterion comment="alt-python27-tools is earlier than 0:2.7.18-41.el9" test_ref="oval:com.tuxcare.clsa:tst:1786541588007"/>
        <criterion comment="alt-python27-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1753804881014"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1786542344" version="1">
      <metadata>
        <title>alt-python38: Fix of 4 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1786542344" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1786542344" source="CLSA"/>
        <reference ref_id="CVE-2026-4360" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4360" source="CVE"/>
        <reference ref_id="CVE-2026-0864" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" source="CVE"/>
        <reference ref_id="CVE-2026-11972" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" source="CVE"/>
        <reference ref_id="CVE-2026-11940" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" source="CVE"/>
        <description>- CVE-2026-11940: tarfile: fix extraction-filter bypass via the
  hardlink-to-symlink extraction fallback; makelink_with_filter now re-runs
  the filter on the member re-rooted at the link's own path, so a crafted
  archive can no longer recreate a validated deeper symlink at a shallower
  path escaping the destination (incomplete fix of CVE-2025-4330)
- CVE-2026-0864: configparser: normalize all line endings (CR, CRLF, LF) to
  '\n\t' when writing, preventing injection of unexpected keys, values, or
  sections through carriage returns in written values
- CVE-2026-11972: tarfile: break _Stream.seek() at EOF in streaming mode
  (mode="r|"), preventing a CPU denial-of-service when a forged member
  header declares a huge size against an already-exhausted stream
- CVE-2026-4360: tarfile: forward filter_function from TarFile.extract() to
  _extract_one(), so the hardlink/symlink extraction fallback applies the
  extraction filter on the single-member extract() path too; previously
  attacker-controlled mode, uid and gid were applied verbatim even with
  filter='data' and the CVE-2025-4330/CVE-2026-11940 fallback checks never
  ran there (cpython 7ccdbaba, gh-151987, follow-up to gh-151558)</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-12"/>
          <updated date="2026-08-12"/>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-281" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4360" impact="moderate" public="20260630">CVE-2026-4360</cve>
          <cve cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" impact="unknown" public="20260623">CVE-2026-0864</cve>
          <cve cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" impact="unknown" public="20260623">CVE-2026-11972</cve>
          <cve cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" impact="unknown" public="20260623">CVE-2026-11940</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python38 is earlier than 0:3.8.20-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1786542344001"/>
        <criterion comment="alt-python38 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097002"/>
        <criterion comment="alt-python38-devel is earlier than 0:3.8.20-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1786542344002"/>
        <criterion comment="alt-python38-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097004"/>
        <criterion comment="alt-python38-idle is earlier than 0:3.8.20-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1786542344003"/>
        <criterion comment="alt-python38-idle isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097006"/>
        <criterion comment="alt-python38-libs is earlier than 0:3.8.20-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1786542344004"/>
        <criterion comment="alt-python38-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097008"/>
        <criterion comment="alt-python38-test is earlier than 0:3.8.20-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1786542344005"/>
        <criterion comment="alt-python38-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097010"/>
        <criterion comment="alt-python38-tkinter is earlier than 0:3.8.20-22.el9" test_ref="oval:com.tuxcare.clsa:tst:1786542344006"/>
        <criterion comment="alt-python38-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1784298097012"/>
      </criteria>
    </definition>
    <definition class="patch" id="oval:com.tuxcare.clsa:def:1786555316" version="1">
      <metadata>
        <title>alt-python36: Fix of 7 CVEs</title>
        <affected family="unix">
          <platform>Community Enterprise Operating System 9</platform>
        </affected>
        <reference ref_id="CLSA-2026:1786555316" ref_url="https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1786555316" source="CLSA"/>
        <reference ref_id="CVE-2026-4360" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4360" source="CVE"/>
        <reference ref_id="CVE-2026-0864" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" source="CVE"/>
        <reference ref_id="CVE-2026-11972" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" source="CVE"/>
        <reference ref_id="CVE-2026-3276" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" source="CVE"/>
        <reference ref_id="CVE-2026-8328" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" source="CVE"/>
        <reference ref_id="CVE-2026-11940" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" source="CVE"/>
        <reference ref_id="CVE-2026-7774" ref_url="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" source="CVE"/>
        <description>- CVE-2026-7774: tarfile: fix data_filter bypass via crafted link entries;
  validate the normalised link target that is actually written to disk,
  resolve symlink targets relative to the member name with trailing
  separators stripped, and reject link members (including symlinks with
  empty or directory-like names) that would replace the destination
  directory itself and redirect later members outside it
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
  ftpcp(): use the source server's real peer address instead of the
  attacker-controllable IPv4 address from the PASV reply unless
  trust_server_pasv_ipv4_address is set</description>
        <advisory from="packager@tuxcare.com">
          <severity>Important</severity>
          <rights>TuxCare License Agreement</rights>
          <issued date="2026-08-12"/>
          <updated date="2026-08-12"/>
          <cve cvss3="5.3/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" cwe="CWE-281" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-4360" impact="moderate" public="20260630">CVE-2026-4360</cve>
          <cve cwe="CWE-74" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-0864" impact="unknown" public="20260623">CVE-2026-0864</cve>
          <cve cwe="CWE-252" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11972" impact="unknown" public="20260623">CVE-2026-11972</cve>
          <cve cwe="CWE-407" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-3276" impact="unknown" public="20260603">CVE-2026-3276</cve>
          <cve cwe="CWE-918" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-8328" impact="unknown" public="20260513">CVE-2026-8328</cve>
          <cve cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-11940" impact="unknown" public="20260623">CVE-2026-11940</cve>
          <cve cwe="CWE-22" href="https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-7774" impact="unknown" public="20260604">CVE-2026-7774</cve>
          <affected_cpe_list>
            <cpe>cpe:/o:centos:centos:9</cpe>
          </affected_cpe_list>
        </advisory>
      </metadata>
      <criteria operator="OR">
        <criterion comment="alt-python36 is earlier than 0:3.6.15-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1786555316001"/>
        <criterion comment="alt-python36 isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587002"/>
        <criterion comment="alt-python36-debug is earlier than 0:3.6.15-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1786555316002"/>
        <criterion comment="alt-python36-debug isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587004"/>
        <criterion comment="alt-python36-devel is earlier than 0:3.6.15-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1786555316003"/>
        <criterion comment="alt-python36-devel isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587006"/>
        <criterion comment="alt-python36-libs is earlier than 0:3.6.15-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1786555316004"/>
        <criterion comment="alt-python36-libs isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587008"/>
        <criterion comment="alt-python36-test is earlier than 0:3.6.15-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1786555316005"/>
        <criterion comment="alt-python36-test isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587010"/>
        <criterion comment="alt-python36-tkinter is earlier than 0:3.6.15-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1786555316006"/>
        <criterion comment="alt-python36-tkinter isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587012"/>
        <criterion comment="alt-python36-tools is earlier than 0:3.6.15-34.el9" test_ref="oval:com.tuxcare.clsa:tst:1786555316007"/>
        <criterion comment="alt-python36-tools isn't signed with TuxCare key" test_ref="oval:com.tuxcare.clsa:tst:1748352587014"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-6.el9" id="oval:com.tuxcare.clsa:tst:1748352587001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1748352587002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-6.el9" id="oval:com.tuxcare.clsa:tst:1748352587003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-debug isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1748352587004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-6.el9" id="oval:com.tuxcare.clsa:tst:1748352587005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1748352587006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-6.el9" id="oval:com.tuxcare.clsa:tst:1748352587007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1748352587008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-6.el9" id="oval:com.tuxcare.clsa:tst:1748352587009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-test isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1748352587010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-6.el9" id="oval:com.tuxcare.clsa:tst:1748352587011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-tkinter isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1748352587012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-6.el9" id="oval:com.tuxcare.clsa:tst:1748352587013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-tools isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1748352587014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-7.el9" id="oval:com.tuxcare.clsa:tst:1749037854001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1749037854001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-7.el9" id="oval:com.tuxcare.clsa:tst:1749037854002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1749037854001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-7.el9" id="oval:com.tuxcare.clsa:tst:1749037854003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1749037854001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-7.el9" id="oval:com.tuxcare.clsa:tst:1749037854004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1749037854001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-7.el9" id="oval:com.tuxcare.clsa:tst:1749037854005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1749037854001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-7.el9" id="oval:com.tuxcare.clsa:tst:1749037854006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1749037854001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-7.el9" id="oval:com.tuxcare.clsa:tst:1749037854007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1749037854001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-8.el9" id="oval:com.tuxcare.clsa:tst:1753205878001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753205878001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-8.el9" id="oval:com.tuxcare.clsa:tst:1753205878002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753205878001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-8.el9" id="oval:com.tuxcare.clsa:tst:1753205878003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753205878001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-8.el9" id="oval:com.tuxcare.clsa:tst:1753205878004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753205878001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-8.el9" id="oval:com.tuxcare.clsa:tst:1753205878005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753205878001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-8.el9" id="oval:com.tuxcare.clsa:tst:1753205878006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753205878001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-8.el9" id="oval:com.tuxcare.clsa:tst:1753205878007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753205878001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-14.el9" id="oval:com.tuxcare.clsa:tst:1753804881001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753804881001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python27 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1753804881002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-14.el9" id="oval:com.tuxcare.clsa:tst:1753804881003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753804881001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python27-debug isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1753804881004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-14.el9" id="oval:com.tuxcare.clsa:tst:1753804881005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753804881001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python27-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1753804881006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-14.el9" id="oval:com.tuxcare.clsa:tst:1753804881007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753804881001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python27-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1753804881008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-14.el9" id="oval:com.tuxcare.clsa:tst:1753804881009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753804881001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python27-test isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1753804881010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-14.el9" id="oval:com.tuxcare.clsa:tst:1753804881011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753804881001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python27-tkinter isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1753804881012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-14.el9" id="oval:com.tuxcare.clsa:tst:1753804881013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1753804881001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python27-tools isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1753804881014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-16.el9" id="oval:com.tuxcare.clsa:tst:1754039871001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1754039871001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-16.el9" id="oval:com.tuxcare.clsa:tst:1754039871002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1754039871001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-16.el9" id="oval:com.tuxcare.clsa:tst:1754039871003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1754039871001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-16.el9" id="oval:com.tuxcare.clsa:tst:1754039871004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1754039871001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-16.el9" id="oval:com.tuxcare.clsa:tst:1754039871005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1754039871001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-16.el9" id="oval:com.tuxcare.clsa:tst:1754039871006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1754039871001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-16.el9" id="oval:com.tuxcare.clsa:tst:1754039871007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1754039871001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-20.el9" id="oval:com.tuxcare.clsa:tst:1760098218001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760098218001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-20.el9" id="oval:com.tuxcare.clsa:tst:1760098218002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760098218001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-20.el9" id="oval:com.tuxcare.clsa:tst:1760098218003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760098218001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-20.el9" id="oval:com.tuxcare.clsa:tst:1760098218004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760098218001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-20.el9" id="oval:com.tuxcare.clsa:tst:1760098218005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760098218001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-20.el9" id="oval:com.tuxcare.clsa:tst:1760098218006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760098218001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-20.el9" id="oval:com.tuxcare.clsa:tst:1760098218007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760098218001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-21.el9" id="oval:com.tuxcare.clsa:tst:1760369183001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760369183001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-21.el9" id="oval:com.tuxcare.clsa:tst:1760369183002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760369183001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-21.el9" id="oval:com.tuxcare.clsa:tst:1760369183003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760369183001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-21.el9" id="oval:com.tuxcare.clsa:tst:1760369183004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760369183001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-21.el9" id="oval:com.tuxcare.clsa:tst:1760369183005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760369183001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-21.el9" id="oval:com.tuxcare.clsa:tst:1760369183006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760369183001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-21.el9" id="oval:com.tuxcare.clsa:tst:1760369183007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1760369183001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-13.el9" id="oval:com.tuxcare.clsa:tst:1762528386001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1762528386001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-13.el9" id="oval:com.tuxcare.clsa:tst:1762528386002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1762528386001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-13.el9" id="oval:com.tuxcare.clsa:tst:1762528386003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1762528386001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-13.el9" id="oval:com.tuxcare.clsa:tst:1762528386004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1762528386001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-13.el9" id="oval:com.tuxcare.clsa:tst:1762528386005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1762528386001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-13.el9" id="oval:com.tuxcare.clsa:tst:1762528386006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1762528386001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-13.el9" id="oval:com.tuxcare.clsa:tst:1762528386007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1762528386001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-16.el9" id="oval:com.tuxcare.clsa:tst:1771339135001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1771339135001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-16.el9" id="oval:com.tuxcare.clsa:tst:1771339135002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1771339135001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-16.el9" id="oval:com.tuxcare.clsa:tst:1771339135003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1771339135001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-16.el9" id="oval:com.tuxcare.clsa:tst:1771339135004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1771339135001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-16.el9" id="oval:com.tuxcare.clsa:tst:1771339135005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1771339135001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-16.el9" id="oval:com.tuxcare.clsa:tst:1771339135006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1771339135001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-16.el9" id="oval:com.tuxcare.clsa:tst:1771339135007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1771339135001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-22.el9" id="oval:com.tuxcare.clsa:tst:1772111352001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772111352001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-22.el9" id="oval:com.tuxcare.clsa:tst:1772111352002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772111352001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-22.el9" id="oval:com.tuxcare.clsa:tst:1772111352003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772111352001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-22.el9" id="oval:com.tuxcare.clsa:tst:1772111352004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772111352001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-22.el9" id="oval:com.tuxcare.clsa:tst:1772111352005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772111352001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-22.el9" id="oval:com.tuxcare.clsa:tst:1772111352006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772111352001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-22.el9" id="oval:com.tuxcare.clsa:tst:1772111352007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772111352001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-17.el9" id="oval:com.tuxcare.clsa:tst:1772139704001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772139704001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-17.el9" id="oval:com.tuxcare.clsa:tst:1772139704002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772139704001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-17.el9" id="oval:com.tuxcare.clsa:tst:1772139704003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772139704001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-17.el9" id="oval:com.tuxcare.clsa:tst:1772139704004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772139704001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-17.el9" id="oval:com.tuxcare.clsa:tst:1772139704005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772139704001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-17.el9" id="oval:com.tuxcare.clsa:tst:1772139704006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772139704001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-17.el9" id="oval:com.tuxcare.clsa:tst:1772139704007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772139704001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-23.el9" id="oval:com.tuxcare.clsa:tst:1772188508001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772188508001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-23.el9" id="oval:com.tuxcare.clsa:tst:1772188508002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772188508001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-23.el9" id="oval:com.tuxcare.clsa:tst:1772188508003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772188508001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-23.el9" id="oval:com.tuxcare.clsa:tst:1772188508004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772188508001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-23.el9" id="oval:com.tuxcare.clsa:tst:1772188508005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772188508001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-23.el9" id="oval:com.tuxcare.clsa:tst:1772188508006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772188508001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-23.el9" id="oval:com.tuxcare.clsa:tst:1772188508007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772188508001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-18.el9" id="oval:com.tuxcare.clsa:tst:1772446514001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772446514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-18.el9" id="oval:com.tuxcare.clsa:tst:1772446514002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772446514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-18.el9" id="oval:com.tuxcare.clsa:tst:1772446514003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772446514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-18.el9" id="oval:com.tuxcare.clsa:tst:1772446514004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772446514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-18.el9" id="oval:com.tuxcare.clsa:tst:1772446514005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772446514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-18.el9" id="oval:com.tuxcare.clsa:tst:1772446514006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772446514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-18.el9" id="oval:com.tuxcare.clsa:tst:1772446514007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772446514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-19.el9" id="oval:com.tuxcare.clsa:tst:1772559514001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772559514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-19.el9" id="oval:com.tuxcare.clsa:tst:1772559514002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772559514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-19.el9" id="oval:com.tuxcare.clsa:tst:1772559514003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772559514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-19.el9" id="oval:com.tuxcare.clsa:tst:1772559514004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772559514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-19.el9" id="oval:com.tuxcare.clsa:tst:1772559514005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772559514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-19.el9" id="oval:com.tuxcare.clsa:tst:1772559514006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772559514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-19.el9" id="oval:com.tuxcare.clsa:tst:1772559514007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772559514001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-24.el9" id="oval:com.tuxcare.clsa:tst:1772721745001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772721745001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-24.el9" id="oval:com.tuxcare.clsa:tst:1772721745002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772721745001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-24.el9" id="oval:com.tuxcare.clsa:tst:1772721745003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772721745001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-24.el9" id="oval:com.tuxcare.clsa:tst:1772721745004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772721745001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-24.el9" id="oval:com.tuxcare.clsa:tst:1772721745005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772721745001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-24.el9" id="oval:com.tuxcare.clsa:tst:1772721745006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772721745001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-24.el9" id="oval:com.tuxcare.clsa:tst:1772721745007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1772721745001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-25.el9" id="oval:com.tuxcare.clsa:tst:1773240322001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1773240322001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-25.el9" id="oval:com.tuxcare.clsa:tst:1773240322002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1773240322001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-25.el9" id="oval:com.tuxcare.clsa:tst:1773240322003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1773240322001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-25.el9" id="oval:com.tuxcare.clsa:tst:1773240322004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1773240322001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-25.el9" id="oval:com.tuxcare.clsa:tst:1773240322005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1773240322001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-25.el9" id="oval:com.tuxcare.clsa:tst:1773240322006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1773240322001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-25.el9" id="oval:com.tuxcare.clsa:tst:1773240322007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1773240322001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-20.el9" id="oval:com.tuxcare.clsa:tst:1776434771001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776434771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-20.el9" id="oval:com.tuxcare.clsa:tst:1776434771002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776434771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-20.el9" id="oval:com.tuxcare.clsa:tst:1776434771003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776434771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-20.el9" id="oval:com.tuxcare.clsa:tst:1776434771004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776434771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-20.el9" id="oval:com.tuxcare.clsa:tst:1776434771005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776434771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-20.el9" id="oval:com.tuxcare.clsa:tst:1776434771006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776434771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-20.el9" id="oval:com.tuxcare.clsa:tst:1776434771007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1776434771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-27.el9" id="oval:com.tuxcare.clsa:tst:1777047108001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777047108001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-27.el9" id="oval:com.tuxcare.clsa:tst:1777047108002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777047108001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-27.el9" id="oval:com.tuxcare.clsa:tst:1777047108003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777047108001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-27.el9" id="oval:com.tuxcare.clsa:tst:1777047108004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777047108001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-27.el9" id="oval:com.tuxcare.clsa:tst:1777047108005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777047108001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-27.el9" id="oval:com.tuxcare.clsa:tst:1777047108006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777047108001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-27.el9" id="oval:com.tuxcare.clsa:tst:1777047108007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777047108001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-21.el9" id="oval:com.tuxcare.clsa:tst:1777390475001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777390475001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-21.el9" id="oval:com.tuxcare.clsa:tst:1777390475002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777390475001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-21.el9" id="oval:com.tuxcare.clsa:tst:1777390475003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777390475001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-21.el9" id="oval:com.tuxcare.clsa:tst:1777390475004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777390475001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-21.el9" id="oval:com.tuxcare.clsa:tst:1777390475005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777390475001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-21.el9" id="oval:com.tuxcare.clsa:tst:1777390475006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777390475001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-21.el9" id="oval:com.tuxcare.clsa:tst:1777390475007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777390475001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-29.el9" id="oval:com.tuxcare.clsa:tst:1777478783001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777478783001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-29.el9" id="oval:com.tuxcare.clsa:tst:1777478783002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777478783001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-29.el9" id="oval:com.tuxcare.clsa:tst:1777478783003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777478783001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-29.el9" id="oval:com.tuxcare.clsa:tst:1777478783004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777478783001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-29.el9" id="oval:com.tuxcare.clsa:tst:1777478783005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777478783001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-29.el9" id="oval:com.tuxcare.clsa:tst:1777478783006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777478783001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-29.el9" id="oval:com.tuxcare.clsa:tst:1777478783007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777478783001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-30.el9" id="oval:com.tuxcare.clsa:tst:1777630510001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777630510001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-30.el9" id="oval:com.tuxcare.clsa:tst:1777630510002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777630510001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-30.el9" id="oval:com.tuxcare.clsa:tst:1777630510003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777630510001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-30.el9" id="oval:com.tuxcare.clsa:tst:1777630510004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777630510001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-30.el9" id="oval:com.tuxcare.clsa:tst:1777630510005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777630510001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-30.el9" id="oval:com.tuxcare.clsa:tst:1777630510006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777630510001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-30.el9" id="oval:com.tuxcare.clsa:tst:1777630510007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777630510001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-22.el9" id="oval:com.tuxcare.clsa:tst:1777637454001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777637454001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-22.el9" id="oval:com.tuxcare.clsa:tst:1777637454002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777637454001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-22.el9" id="oval:com.tuxcare.clsa:tst:1777637454003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777637454001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-22.el9" id="oval:com.tuxcare.clsa:tst:1777637454004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777637454001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-22.el9" id="oval:com.tuxcare.clsa:tst:1777637454005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777637454001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-22.el9" id="oval:com.tuxcare.clsa:tst:1777637454006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777637454001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-22.el9" id="oval:com.tuxcare.clsa:tst:1777637454007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1777637454001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-23.el9" id="oval:com.tuxcare.clsa:tst:1778161965001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778161965001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-23.el9" id="oval:com.tuxcare.clsa:tst:1778161965002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778161965001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-23.el9" id="oval:com.tuxcare.clsa:tst:1778161965003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778161965001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-23.el9" id="oval:com.tuxcare.clsa:tst:1778161965004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778161965001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-23.el9" id="oval:com.tuxcare.clsa:tst:1778161965005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778161965001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-23.el9" id="oval:com.tuxcare.clsa:tst:1778161965006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778161965001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-23.el9" id="oval:com.tuxcare.clsa:tst:1778161965007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778161965001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-31.el9" id="oval:com.tuxcare.clsa:tst:1778245330001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778245330001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-31.el9" id="oval:com.tuxcare.clsa:tst:1778245330002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778245330001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-31.el9" id="oval:com.tuxcare.clsa:tst:1778245330003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778245330001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-31.el9" id="oval:com.tuxcare.clsa:tst:1778245330004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778245330001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-31.el9" id="oval:com.tuxcare.clsa:tst:1778245330005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778245330001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-31.el9" id="oval:com.tuxcare.clsa:tst:1778245330006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778245330001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-31.el9" id="oval:com.tuxcare.clsa:tst:1778245330007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1778245330001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-24.el9" id="oval:com.tuxcare.clsa:tst:1779278705001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779278705001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-24.el9" id="oval:com.tuxcare.clsa:tst:1779278705002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779278705001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-24.el9" id="oval:com.tuxcare.clsa:tst:1779278705003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779278705001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-24.el9" id="oval:com.tuxcare.clsa:tst:1779278705004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779278705001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-24.el9" id="oval:com.tuxcare.clsa:tst:1779278705005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779278705001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-24.el9" id="oval:com.tuxcare.clsa:tst:1779278705006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779278705001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-24.el9" id="oval:com.tuxcare.clsa:tst:1779278705007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779278705001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-32.el9" id="oval:com.tuxcare.clsa:tst:1779463938001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779463938001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-32.el9" id="oval:com.tuxcare.clsa:tst:1779463938002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779463938001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-32.el9" id="oval:com.tuxcare.clsa:tst:1779463938003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779463938001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-32.el9" id="oval:com.tuxcare.clsa:tst:1779463938004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779463938001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-32.el9" id="oval:com.tuxcare.clsa:tst:1779463938005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779463938001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-32.el9" id="oval:com.tuxcare.clsa:tst:1779463938006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779463938001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-32.el9" id="oval:com.tuxcare.clsa:tst:1779463938007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779463938001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-25.el9" id="oval:com.tuxcare.clsa:tst:1779880402001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779880402001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-25.el9" id="oval:com.tuxcare.clsa:tst:1779880402002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779880402001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-25.el9" id="oval:com.tuxcare.clsa:tst:1779880402003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779880402001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-25.el9" id="oval:com.tuxcare.clsa:tst:1779880402004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779880402001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-25.el9" id="oval:com.tuxcare.clsa:tst:1779880402005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779880402001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-25.el9" id="oval:com.tuxcare.clsa:tst:1779880402006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779880402001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-25.el9" id="oval:com.tuxcare.clsa:tst:1779880402007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779880402001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-33.el9" id="oval:com.tuxcare.clsa:tst:1779887983001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779887983001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-33.el9" id="oval:com.tuxcare.clsa:tst:1779887983002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779887983001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-33.el9" id="oval:com.tuxcare.clsa:tst:1779887983003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779887983001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-33.el9" id="oval:com.tuxcare.clsa:tst:1779887983004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779887983001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-33.el9" id="oval:com.tuxcare.clsa:tst:1779887983005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779887983001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-33.el9" id="oval:com.tuxcare.clsa:tst:1779887983006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779887983001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-33.el9" id="oval:com.tuxcare.clsa:tst:1779887983007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1779887983001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-28.el9" id="oval:com.tuxcare.clsa:tst:1780516373001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1780516373001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-28.el9" id="oval:com.tuxcare.clsa:tst:1780516373002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1780516373001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-28.el9" id="oval:com.tuxcare.clsa:tst:1780516373003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1780516373001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-28.el9" id="oval:com.tuxcare.clsa:tst:1780516373004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1780516373001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-28.el9" id="oval:com.tuxcare.clsa:tst:1780516373005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1780516373001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-28.el9" id="oval:com.tuxcare.clsa:tst:1780516373006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1780516373001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-28.el9" id="oval:com.tuxcare.clsa:tst:1780516373007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1780516373001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-34.el9" id="oval:com.tuxcare.clsa:tst:1781103532001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781103532001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-34.el9" id="oval:com.tuxcare.clsa:tst:1781103532002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781103532001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-34.el9" id="oval:com.tuxcare.clsa:tst:1781103532003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781103532001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-34.el9" id="oval:com.tuxcare.clsa:tst:1781103532004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781103532001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-34.el9" id="oval:com.tuxcare.clsa:tst:1781103532005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781103532001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-34.el9" id="oval:com.tuxcare.clsa:tst:1781103532006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781103532001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-34.el9" id="oval:com.tuxcare.clsa:tst:1781103532007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781103532001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-29.el9" id="oval:com.tuxcare.clsa:tst:1781521190001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781521190001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-29.el9" id="oval:com.tuxcare.clsa:tst:1781521190002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781521190001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-29.el9" id="oval:com.tuxcare.clsa:tst:1781521190003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781521190001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-29.el9" id="oval:com.tuxcare.clsa:tst:1781521190004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781521190001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-29.el9" id="oval:com.tuxcare.clsa:tst:1781521190005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781521190001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-29.el9" id="oval:com.tuxcare.clsa:tst:1781521190006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781521190001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-29.el9" id="oval:com.tuxcare.clsa:tst:1781521190007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1781521190001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-30.el9" id="oval:com.tuxcare.clsa:tst:1782297615001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782297615001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-30.el9" id="oval:com.tuxcare.clsa:tst:1782297615002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782297615001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-30.el9" id="oval:com.tuxcare.clsa:tst:1782297615003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782297615001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-30.el9" id="oval:com.tuxcare.clsa:tst:1782297615004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782297615001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-30.el9" id="oval:com.tuxcare.clsa:tst:1782297615005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782297615001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-30.el9" id="oval:com.tuxcare.clsa:tst:1782297615006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782297615001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-30.el9" id="oval:com.tuxcare.clsa:tst:1782297615007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782297615001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-35.el9" id="oval:com.tuxcare.clsa:tst:1782998840001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782998840001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-35.el9" id="oval:com.tuxcare.clsa:tst:1782998840002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782998840001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-35.el9" id="oval:com.tuxcare.clsa:tst:1782998840003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782998840001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-35.el9" id="oval:com.tuxcare.clsa:tst:1782998840004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782998840001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-35.el9" id="oval:com.tuxcare.clsa:tst:1782998840005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782998840001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-35.el9" id="oval:com.tuxcare.clsa:tst:1782998840006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782998840001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-35.el9" id="oval:com.tuxcare.clsa:tst:1782998840007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1782998840001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-37.el9" id="oval:com.tuxcare.clsa:tst:1783343295001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1783343295001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-37.el9" id="oval:com.tuxcare.clsa:tst:1783343295002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1783343295001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-37.el9" id="oval:com.tuxcare.clsa:tst:1783343295003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1783343295001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-37.el9" id="oval:com.tuxcare.clsa:tst:1783343295004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1783343295001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-37.el9" id="oval:com.tuxcare.clsa:tst:1783343295005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1783343295001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-37.el9" id="oval:com.tuxcare.clsa:tst:1783343295006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1783343295001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-37.el9" id="oval:com.tuxcare.clsa:tst:1783343295007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1783343295001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38 is earlier than 0:3.8.20-19.el9" id="oval:com.tuxcare.clsa:tst:1784298097001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784298097001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784298097002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-devel is earlier than 0:3.8.20-19.el9" id="oval:com.tuxcare.clsa:tst:1784298097003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784298097001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784298097004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-idle is earlier than 0:3.8.20-19.el9" id="oval:com.tuxcare.clsa:tst:1784298097005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784298097001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-idle isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784298097006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-libs is earlier than 0:3.8.20-19.el9" id="oval:com.tuxcare.clsa:tst:1784298097007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784298097001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784298097008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-test is earlier than 0:3.8.20-19.el9" id="oval:com.tuxcare.clsa:tst:1784298097009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784298097001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-test isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784298097010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-tkinter is earlier than 0:3.8.20-19.el9" id="oval:com.tuxcare.clsa:tst:1784298097011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784298097001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-tkinter isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784298097012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39 is earlier than 0:3.9.23-17.el9" id="oval:com.tuxcare.clsa:tst:1784300728001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784300728001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784300728002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-debug is earlier than 0:3.9.23-17.el9" id="oval:com.tuxcare.clsa:tst:1784300728003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784300728001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-debug isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784300728004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-devel is earlier than 0:3.9.23-17.el9" id="oval:com.tuxcare.clsa:tst:1784300728005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784300728001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784300728006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-idle is earlier than 0:3.9.23-17.el9" id="oval:com.tuxcare.clsa:tst:1784300728007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784300728001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-idle isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784300728008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-libs is earlier than 0:3.9.23-17.el9" id="oval:com.tuxcare.clsa:tst:1784300728009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784300728001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784300728010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-test is earlier than 0:3.9.23-17.el9" id="oval:com.tuxcare.clsa:tst:1784300728011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784300728001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-test isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784300728012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-tkinter is earlier than 0:3.9.23-17.el9" id="oval:com.tuxcare.clsa:tst:1784300728013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784300728001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-tkinter isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784300728014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311 is earlier than 0:3.11.15-1.el9" id="oval:com.tuxcare.clsa:tst:1784311073001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784311073001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784311073002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-debug is earlier than 0:3.11.15-1.el9" id="oval:com.tuxcare.clsa:tst:1784311073003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784311073001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-debug isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784311073004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-devel is earlier than 0:3.11.15-1.el9" id="oval:com.tuxcare.clsa:tst:1784311073005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784311073001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784311073006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-idle is earlier than 0:3.11.15-1.el9" id="oval:com.tuxcare.clsa:tst:1784311073007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784311073001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-idle isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784311073008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-libs is earlier than 0:3.11.15-1.el9" id="oval:com.tuxcare.clsa:tst:1784311073009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784311073001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784311073010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-test is earlier than 0:3.11.15-1.el9" id="oval:com.tuxcare.clsa:tst:1784311073011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784311073001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-test isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784311073012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-tkinter is earlier than 0:3.11.15-1.el9" id="oval:com.tuxcare.clsa:tst:1784311073013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784311073001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-tkinter isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784311073014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-1.el9" id="oval:com.tuxcare.clsa:tst:1784312324001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784312324001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310 isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784312324002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-1.el9" id="oval:com.tuxcare.clsa:tst:1784312324003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784312324001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-debug isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784312324004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-1.el9" id="oval:com.tuxcare.clsa:tst:1784312324005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784312324001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-devel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784312324006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-1.el9" id="oval:com.tuxcare.clsa:tst:1784312324007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784312324001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-idle isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784312324008" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-1.el9" id="oval:com.tuxcare.clsa:tst:1784312324009" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784312324001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-libs isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784312324010" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-1.el9" id="oval:com.tuxcare.clsa:tst:1784312324011" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784312324001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-test isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784312324012" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-1.el9" id="oval:com.tuxcare.clsa:tst:1784312324013" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784312324001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-tkinter isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784312324014" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-setuptools is earlier than 0:58.3.0-3.el9" id="oval:com.tuxcare.clsa:tst:1784372957001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784372957001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784372957001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-setuptools isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784372957002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784372957001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-setuptools-wheel is earlier than 0:58.3.0-3.el9" id="oval:com.tuxcare.clsa:tst:1784372957003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784372957003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784372957001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-setuptools-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1784372957004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784372957003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-2.el9" id="oval:com.tuxcare.clsa:tst:1784800604001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784800604001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-2.el9" id="oval:com.tuxcare.clsa:tst:1784800604002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784800604001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-2.el9" id="oval:com.tuxcare.clsa:tst:1784800604003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784800604001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-2.el9" id="oval:com.tuxcare.clsa:tst:1784800604004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784800604001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-2.el9" id="oval:com.tuxcare.clsa:tst:1784800604005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784800604001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-2.el9" id="oval:com.tuxcare.clsa:tst:1784800604006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784800604001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-2.el9" id="oval:com.tuxcare.clsa:tst:1784800604007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784800604001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-38.el9" id="oval:com.tuxcare.clsa:tst:1784804478001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784804478001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-38.el9" id="oval:com.tuxcare.clsa:tst:1784804478002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784804478001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-38.el9" id="oval:com.tuxcare.clsa:tst:1784804478003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784804478001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-38.el9" id="oval:com.tuxcare.clsa:tst:1784804478004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784804478001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-38.el9" id="oval:com.tuxcare.clsa:tst:1784804478005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784804478001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-38.el9" id="oval:com.tuxcare.clsa:tst:1784804478006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784804478001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-38.el9" id="oval:com.tuxcare.clsa:tst:1784804478007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784804478001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39 is earlier than 0:3.9.23-20.el9" id="oval:com.tuxcare.clsa:tst:1784811769001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784811769001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-debug is earlier than 0:3.9.23-20.el9" id="oval:com.tuxcare.clsa:tst:1784811769002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784811769001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-devel is earlier than 0:3.9.23-20.el9" id="oval:com.tuxcare.clsa:tst:1784811769003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784811769001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-idle is earlier than 0:3.9.23-20.el9" id="oval:com.tuxcare.clsa:tst:1784811769004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784811769001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-libs is earlier than 0:3.9.23-20.el9" id="oval:com.tuxcare.clsa:tst:1784811769005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784811769001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-test is earlier than 0:3.9.23-20.el9" id="oval:com.tuxcare.clsa:tst:1784811769006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784811769001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-tkinter is earlier than 0:3.9.23-20.el9" id="oval:com.tuxcare.clsa:tst:1784811769007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784811769001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38 is earlier than 0:3.8.20-21.el9" id="oval:com.tuxcare.clsa:tst:1784815391001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784815391001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-devel is earlier than 0:3.8.20-21.el9" id="oval:com.tuxcare.clsa:tst:1784815391002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784815391001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-idle is earlier than 0:3.8.20-21.el9" id="oval:com.tuxcare.clsa:tst:1784815391003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784815391001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-libs is earlier than 0:3.8.20-21.el9" id="oval:com.tuxcare.clsa:tst:1784815391004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784815391001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-test is earlier than 0:3.8.20-21.el9" id="oval:com.tuxcare.clsa:tst:1784815391005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784815391001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-tkinter is earlier than 0:3.8.20-21.el9" id="oval:com.tuxcare.clsa:tst:1784815391006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784815391001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-31.el9" id="oval:com.tuxcare.clsa:tst:1784822014001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784822014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-31.el9" id="oval:com.tuxcare.clsa:tst:1784822014002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784822014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-31.el9" id="oval:com.tuxcare.clsa:tst:1784822014003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784822014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-31.el9" id="oval:com.tuxcare.clsa:tst:1784822014004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784822014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-31.el9" id="oval:com.tuxcare.clsa:tst:1784822014005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784822014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-31.el9" id="oval:com.tuxcare.clsa:tst:1784822014006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784822014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-31.el9" id="oval:com.tuxcare.clsa:tst:1784822014007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784822014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311 is earlier than 0:3.11.15-3.el9" id="oval:com.tuxcare.clsa:tst:1784823685001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784823685001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-debug is earlier than 0:3.11.15-3.el9" id="oval:com.tuxcare.clsa:tst:1784823685002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784823685001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-devel is earlier than 0:3.11.15-3.el9" id="oval:com.tuxcare.clsa:tst:1784823685003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784823685001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-idle is earlier than 0:3.11.15-3.el9" id="oval:com.tuxcare.clsa:tst:1784823685004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784823685001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-libs is earlier than 0:3.11.15-3.el9" id="oval:com.tuxcare.clsa:tst:1784823685005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784823685001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-test is earlier than 0:3.11.15-3.el9" id="oval:com.tuxcare.clsa:tst:1784823685006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784823685001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-tkinter is earlier than 0:3.11.15-3.el9" id="oval:com.tuxcare.clsa:tst:1784823685007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784823685001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-3.el9" id="oval:com.tuxcare.clsa:tst:1784882920001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784882920001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-3.el9" id="oval:com.tuxcare.clsa:tst:1784882920002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784882920001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-3.el9" id="oval:com.tuxcare.clsa:tst:1784882920003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784882920001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-3.el9" id="oval:com.tuxcare.clsa:tst:1784882920004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784882920001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-3.el9" id="oval:com.tuxcare.clsa:tst:1784882920005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784882920001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-3.el9" id="oval:com.tuxcare.clsa:tst:1784882920006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784882920001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-3.el9" id="oval:com.tuxcare.clsa:tst:1784882920007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784882920001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-4.el9" id="oval:com.tuxcare.clsa:tst:1784902318001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784902318001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-4.el9" id="oval:com.tuxcare.clsa:tst:1784902318002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784902318001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-4.el9" id="oval:com.tuxcare.clsa:tst:1784902318003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784902318001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-4.el9" id="oval:com.tuxcare.clsa:tst:1784902318004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784902318001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-4.el9" id="oval:com.tuxcare.clsa:tst:1784902318005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784902318001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-4.el9" id="oval:com.tuxcare.clsa:tst:1784902318006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784902318001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-4.el9" id="oval:com.tuxcare.clsa:tst:1784902318007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1784902318001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311 is earlier than 0:3.11.15-4.el9" id="oval:com.tuxcare.clsa:tst:1785141727001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785141727001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-debug is earlier than 0:3.11.15-4.el9" id="oval:com.tuxcare.clsa:tst:1785141727002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785141727001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-devel is earlier than 0:3.11.15-4.el9" id="oval:com.tuxcare.clsa:tst:1785141727003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785141727001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-idle is earlier than 0:3.11.15-4.el9" id="oval:com.tuxcare.clsa:tst:1785141727004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785141727001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-libs is earlier than 0:3.11.15-4.el9" id="oval:com.tuxcare.clsa:tst:1785141727005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785141727001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-test is earlier than 0:3.11.15-4.el9" id="oval:com.tuxcare.clsa:tst:1785141727006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785141727001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-tkinter is earlier than 0:3.11.15-4.el9" id="oval:com.tuxcare.clsa:tst:1785141727007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785141727001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-setuptools is earlier than 0:38.5.2-9.el9" id="oval:com.tuxcare.clsa:tst:1785148862001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785148862001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785148862001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-setuptools isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785148862002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785148862001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-pip is earlier than 0:21.3.1-6.el9" id="oval:com.tuxcare.clsa:tst:1785171014001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171014001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785171014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-pip isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785171014002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171014001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-pip-wheel is earlier than 0:21.3.1-6.el9" id="oval:com.tuxcare.clsa:tst:1785171014003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171014003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785171014001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-pip-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785171014004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171014003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-pip is earlier than 0:21.3.1-5.el9" id="oval:com.tuxcare.clsa:tst:1785171898001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171898001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785171898001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-pip isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785171898002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171898001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-pip-wheel is earlier than 0:21.3.1-5.el9" id="oval:com.tuxcare.clsa:tst:1785171898003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171898003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785171898001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-pip-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785171898004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785171898003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-pip is earlier than 0:22.2.1-5.el9" id="oval:com.tuxcare.clsa:tst:1785173409001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785173409001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785173409001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-pip isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785173409002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785173409001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-pip-wheel is earlier than 0:22.2.1-5.el9" id="oval:com.tuxcare.clsa:tst:1785173409003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785173409003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785173409001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-pip-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785173409004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785173409003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-wheel is earlier than 1:0.37.1-3.el9" id="oval:com.tuxcare.clsa:tst:1785228248001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785228248001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785228248001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785228248002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785228248001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-wheel-wheel is earlier than 1:0.37.1-3.el9" id="oval:com.tuxcare.clsa:tst:1785228248003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785228248003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785228248001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python38-wheel-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785228248004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785228248003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-setuptools is earlier than 0:58.3.0-5.el9" id="oval:com.tuxcare.clsa:tst:1785230640001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785230640001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785230640001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-setuptools isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785230640002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785230640001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-setuptools-wheel is earlier than 0:58.3.0-5.el9" id="oval:com.tuxcare.clsa:tst:1785230640003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785230640003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785230640001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-setuptools-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785230640004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785230640003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-wheel is earlier than 0:0.37.0-2.el9" id="oval:com.tuxcare.clsa:tst:1785237053001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785237053001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785237053001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785237053002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785237053001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-wheel-wheel is earlier than 0:0.37.0-2.el9" id="oval:com.tuxcare.clsa:tst:1785237053003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785237053003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785237053001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-wheel-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785237053004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785237053003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-setuptools is earlier than 0:65.6.3-4.el9" id="oval:com.tuxcare.clsa:tst:1785241961001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785241961001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785241961001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-setuptools isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785241961002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785241961001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-setuptools-wheel is earlier than 0:65.6.3-4.el9" id="oval:com.tuxcare.clsa:tst:1785241961003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785241961003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785241961001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python311-setuptools-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785241961004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785241961003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-wheel is earlier than 0:0.37.0-4.el9" id="oval:com.tuxcare.clsa:tst:1785310634001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785310634001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785310634001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785310634002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785310634001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-wheel-wheel is earlier than 0:0.37.0-4.el9" id="oval:com.tuxcare.clsa:tst:1785310634003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785310634003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785310634001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-wheel-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785310634004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785310634003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-wheel is earlier than 0:0.31.1-2.el9" id="oval:com.tuxcare.clsa:tst:1785315201001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785315201001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785315201001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785315201002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785315201001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-wheel-wheel is earlier than 0:0.31.1-2.el9" id="oval:com.tuxcare.clsa:tst:1785315201003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785315201003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785315201001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-wheel-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785315201004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785315201003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-wheel is earlier than 0:0.37.0-5.el9" id="oval:com.tuxcare.clsa:tst:1785325771001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785325771001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785325771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785325771002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785325771001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-wheel-wheel is earlier than 0:0.37.0-5.el9" id="oval:com.tuxcare.clsa:tst:1785325771003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785325771003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785325771001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-wheel-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785325771004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785325771003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-setuptools is earlier than 0:58.3.0-5.el9" id="oval:com.tuxcare.clsa:tst:1785330970001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785330970001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785230640001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-setuptools isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785330970002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785330970001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-setuptools-wheel is earlier than 0:58.3.0-5.el9" id="oval:com.tuxcare.clsa:tst:1785330970003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785330970003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785230640001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python310-setuptools-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785330970004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785330970003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-pip is earlier than 0:21.3.1-4.el9" id="oval:com.tuxcare.clsa:tst:1785335543001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785335543001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785335543001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-pip isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785335543002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785335543001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-pip-wheel is earlier than 0:21.3.1-4.el9" id="oval:com.tuxcare.clsa:tst:1785335543003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785335543003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785335543001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python39-pip-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785335543004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785335543003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311 is earlier than 0:3.11.15-5.el9" id="oval:com.tuxcare.clsa:tst:1785342083001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785342083001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-debug is earlier than 0:3.11.15-5.el9" id="oval:com.tuxcare.clsa:tst:1785342083002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785342083001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-devel is earlier than 0:3.11.15-5.el9" id="oval:com.tuxcare.clsa:tst:1785342083003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785342083001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-idle is earlier than 0:3.11.15-5.el9" id="oval:com.tuxcare.clsa:tst:1785342083004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785342083001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-libs is earlier than 0:3.11.15-5.el9" id="oval:com.tuxcare.clsa:tst:1785342083005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785342083001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-test is earlier than 0:3.11.15-5.el9" id="oval:com.tuxcare.clsa:tst:1785342083006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785342083001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-tkinter is earlier than 0:3.11.15-5.el9" id="oval:com.tuxcare.clsa:tst:1785342083007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785342083001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39 is earlier than 0:3.9.23-24.el9" id="oval:com.tuxcare.clsa:tst:1785403906001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785403906001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-debug is earlier than 0:3.9.23-24.el9" id="oval:com.tuxcare.clsa:tst:1785403906002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785403906001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-devel is earlier than 0:3.9.23-24.el9" id="oval:com.tuxcare.clsa:tst:1785403906003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785403906001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-idle is earlier than 0:3.9.23-24.el9" id="oval:com.tuxcare.clsa:tst:1785403906004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785403906001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-libs is earlier than 0:3.9.23-24.el9" id="oval:com.tuxcare.clsa:tst:1785403906005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785403906001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-test is earlier than 0:3.9.23-24.el9" id="oval:com.tuxcare.clsa:tst:1785403906006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785403906001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-tkinter is earlier than 0:3.9.23-24.el9" id="oval:com.tuxcare.clsa:tst:1785403906007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785403906001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-pip is earlier than 0:20.2.4-6.el9" id="oval:com.tuxcare.clsa:tst:1785418319001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785418319001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785418319001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-pip isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785418319002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785418319001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-pip-wheel is earlier than 0:20.2.4-6.el9" id="oval:com.tuxcare.clsa:tst:1785418319003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785418319003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785418319001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="none satisfy" comment="alt-python36-pip-wheel isn't signed with TuxCare key" id="oval:com.tuxcare.clsa:tst:1785418319004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785418319003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1748352587002"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39 is earlier than 0:3.9.23-21.el9" id="oval:com.tuxcare.clsa:tst:1785422123001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785422123001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-debug is earlier than 0:3.9.23-21.el9" id="oval:com.tuxcare.clsa:tst:1785422123002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785422123001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-devel is earlier than 0:3.9.23-21.el9" id="oval:com.tuxcare.clsa:tst:1785422123003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785422123001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-idle is earlier than 0:3.9.23-21.el9" id="oval:com.tuxcare.clsa:tst:1785422123004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785422123001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-libs is earlier than 0:3.9.23-21.el9" id="oval:com.tuxcare.clsa:tst:1785422123005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785422123001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-test is earlier than 0:3.9.23-21.el9" id="oval:com.tuxcare.clsa:tst:1785422123006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785422123001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python39-tkinter is earlier than 0:3.9.23-21.el9" id="oval:com.tuxcare.clsa:tst:1785422123007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784300728013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785422123001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310 is earlier than 0:3.10.20-9.el9" id="oval:com.tuxcare.clsa:tst:1785429417001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785429417001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-debug is earlier than 0:3.10.20-9.el9" id="oval:com.tuxcare.clsa:tst:1785429417002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785429417001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-devel is earlier than 0:3.10.20-9.el9" id="oval:com.tuxcare.clsa:tst:1785429417003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785429417001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-idle is earlier than 0:3.10.20-9.el9" id="oval:com.tuxcare.clsa:tst:1785429417004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785429417001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-libs is earlier than 0:3.10.20-9.el9" id="oval:com.tuxcare.clsa:tst:1785429417005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785429417001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-test is earlier than 0:3.10.20-9.el9" id="oval:com.tuxcare.clsa:tst:1785429417006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785429417001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python310-tkinter is earlier than 0:3.10.20-9.el9" id="oval:com.tuxcare.clsa:tst:1785429417007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784312324013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785429417001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311 is earlier than 0:3.11.15-6.el9" id="oval:com.tuxcare.clsa:tst:1785502244001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785502244001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-debug is earlier than 0:3.11.15-6.el9" id="oval:com.tuxcare.clsa:tst:1785502244002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785502244001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-devel is earlier than 0:3.11.15-6.el9" id="oval:com.tuxcare.clsa:tst:1785502244003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785502244001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-idle is earlier than 0:3.11.15-6.el9" id="oval:com.tuxcare.clsa:tst:1785502244004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785502244001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-libs is earlier than 0:3.11.15-6.el9" id="oval:com.tuxcare.clsa:tst:1785502244005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785502244001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-test is earlier than 0:3.11.15-6.el9" id="oval:com.tuxcare.clsa:tst:1785502244006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785502244001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python311-tkinter is earlier than 0:3.11.15-6.el9" id="oval:com.tuxcare.clsa:tst:1785502244007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784311073013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1785502244001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-setuptools is earlier than 0:38.5.2-10.el9" id="oval:com.tuxcare.clsa:tst:1786468319001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1785148862001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786468319001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27 is earlier than 0:2.7.18-41.el9" id="oval:com.tuxcare.clsa:tst:1786541588001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786541588001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-debug is earlier than 0:2.7.18-41.el9" id="oval:com.tuxcare.clsa:tst:1786541588002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786541588001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-devel is earlier than 0:2.7.18-41.el9" id="oval:com.tuxcare.clsa:tst:1786541588003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786541588001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-libs is earlier than 0:2.7.18-41.el9" id="oval:com.tuxcare.clsa:tst:1786541588004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786541588001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-test is earlier than 0:2.7.18-41.el9" id="oval:com.tuxcare.clsa:tst:1786541588005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786541588001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tkinter is earlier than 0:2.7.18-41.el9" id="oval:com.tuxcare.clsa:tst:1786541588006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786541588001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python27-tools is earlier than 0:2.7.18-41.el9" id="oval:com.tuxcare.clsa:tst:1786541588007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1753804881013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786541588001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38 is earlier than 0:3.8.20-22.el9" id="oval:com.tuxcare.clsa:tst:1786542344001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786542344001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-devel is earlier than 0:3.8.20-22.el9" id="oval:com.tuxcare.clsa:tst:1786542344002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786542344001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-idle is earlier than 0:3.8.20-22.el9" id="oval:com.tuxcare.clsa:tst:1786542344003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786542344001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-libs is earlier than 0:3.8.20-22.el9" id="oval:com.tuxcare.clsa:tst:1786542344004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786542344001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-test is earlier than 0:3.8.20-22.el9" id="oval:com.tuxcare.clsa:tst:1786542344005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786542344001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python38-tkinter is earlier than 0:3.8.20-22.el9" id="oval:com.tuxcare.clsa:tst:1786542344006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1784298097011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786542344001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36 is earlier than 0:3.6.15-34.el9" id="oval:com.tuxcare.clsa:tst:1786555316001" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587001"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786555316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-debug is earlier than 0:3.6.15-34.el9" id="oval:com.tuxcare.clsa:tst:1786555316002" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587003"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786555316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-devel is earlier than 0:3.6.15-34.el9" id="oval:com.tuxcare.clsa:tst:1786555316003" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587005"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786555316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-libs is earlier than 0:3.6.15-34.el9" id="oval:com.tuxcare.clsa:tst:1786555316004" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587007"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786555316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-test is earlier than 0:3.6.15-34.el9" id="oval:com.tuxcare.clsa:tst:1786555316005" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587009"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786555316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tkinter is earlier than 0:3.6.15-34.el9" id="oval:com.tuxcare.clsa:tst:1786555316006" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587011"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786555316001"/>
    </red-def:rpminfo_test>
    <red-def:rpminfo_test check="at least one" comment="alt-python36-tools is earlier than 0:3.6.15-34.el9" id="oval:com.tuxcare.clsa:tst:1786555316007" version="1">
      <red-def:object object_ref="oval:com.tuxcare.clsa:obj:1748352587013"/>
      <red-def:state state_ref="oval:com.tuxcare.clsa:ste:1786555316001"/>
    </red-def:rpminfo_test>
  </tests>
  <objects>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1748352587001" version="1">
      <red-def:name>alt-python36</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1748352587003" version="1">
      <red-def:name>alt-python36-debug</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1748352587005" version="1">
      <red-def:name>alt-python36-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1748352587007" version="1">
      <red-def:name>alt-python36-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1748352587009" version="1">
      <red-def:name>alt-python36-test</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1748352587011" version="1">
      <red-def:name>alt-python36-tkinter</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1748352587013" version="1">
      <red-def:name>alt-python36-tools</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1753804881001" version="1">
      <red-def:name>alt-python27</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1753804881003" version="1">
      <red-def:name>alt-python27-debug</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1753804881005" version="1">
      <red-def:name>alt-python27-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1753804881007" version="1">
      <red-def:name>alt-python27-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1753804881009" version="1">
      <red-def:name>alt-python27-test</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1753804881011" version="1">
      <red-def:name>alt-python27-tkinter</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1753804881013" version="1">
      <red-def:name>alt-python27-tools</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784298097001" version="1">
      <red-def:name>alt-python38</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784298097003" version="1">
      <red-def:name>alt-python38-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784298097005" version="1">
      <red-def:name>alt-python38-idle</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784298097007" version="1">
      <red-def:name>alt-python38-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784298097009" version="1">
      <red-def:name>alt-python38-test</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784298097011" version="1">
      <red-def:name>alt-python38-tkinter</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784300728001" version="1">
      <red-def:name>alt-python39</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784300728003" version="1">
      <red-def:name>alt-python39-debug</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784300728005" version="1">
      <red-def:name>alt-python39-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784300728007" version="1">
      <red-def:name>alt-python39-idle</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784300728009" version="1">
      <red-def:name>alt-python39-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784300728011" version="1">
      <red-def:name>alt-python39-test</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784300728013" version="1">
      <red-def:name>alt-python39-tkinter</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784311073001" version="1">
      <red-def:name>alt-python311</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784311073003" version="1">
      <red-def:name>alt-python311-debug</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784311073005" version="1">
      <red-def:name>alt-python311-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784311073007" version="1">
      <red-def:name>alt-python311-idle</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784311073009" version="1">
      <red-def:name>alt-python311-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784311073011" version="1">
      <red-def:name>alt-python311-test</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784311073013" version="1">
      <red-def:name>alt-python311-tkinter</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784312324001" version="1">
      <red-def:name>alt-python310</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784312324003" version="1">
      <red-def:name>alt-python310-debug</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784312324005" version="1">
      <red-def:name>alt-python310-devel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784312324007" version="1">
      <red-def:name>alt-python310-idle</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784312324009" version="1">
      <red-def:name>alt-python310-libs</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784312324011" version="1">
      <red-def:name>alt-python310-test</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784312324013" version="1">
      <red-def:name>alt-python310-tkinter</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784372957001" version="1">
      <red-def:name>alt-python38-setuptools</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1784372957003" version="1">
      <red-def:name>alt-python38-setuptools-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785148862001" version="1">
      <red-def:name>alt-python36-setuptools</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785171014001" version="1">
      <red-def:name>alt-python310-pip</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785171014003" version="1">
      <red-def:name>alt-python310-pip-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785171898001" version="1">
      <red-def:name>alt-python311-pip</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785171898003" version="1">
      <red-def:name>alt-python311-pip-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785173409001" version="1">
      <red-def:name>alt-python38-pip</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785173409003" version="1">
      <red-def:name>alt-python38-pip-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785228248001" version="1">
      <red-def:name>alt-python38-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785228248003" version="1">
      <red-def:name>alt-python38-wheel-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785230640001" version="1">
      <red-def:name>alt-python39-setuptools</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785230640003" version="1">
      <red-def:name>alt-python39-setuptools-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785237053001" version="1">
      <red-def:name>alt-python311-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785237053003" version="1">
      <red-def:name>alt-python311-wheel-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785241961001" version="1">
      <red-def:name>alt-python311-setuptools</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785241961003" version="1">
      <red-def:name>alt-python311-setuptools-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785310634001" version="1">
      <red-def:name>alt-python39-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785310634003" version="1">
      <red-def:name>alt-python39-wheel-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785315201001" version="1">
      <red-def:name>alt-python36-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785315201003" version="1">
      <red-def:name>alt-python36-wheel-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785325771001" version="1">
      <red-def:name>alt-python310-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785325771003" version="1">
      <red-def:name>alt-python310-wheel-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785330970001" version="1">
      <red-def:name>alt-python310-setuptools</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785330970003" version="1">
      <red-def:name>alt-python310-setuptools-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785335543001" version="1">
      <red-def:name>alt-python39-pip</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785335543003" version="1">
      <red-def:name>alt-python39-pip-wheel</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785418319001" version="1">
      <red-def:name>alt-python36-pip</red-def:name>
    </red-def:rpminfo_object>
    <red-def:rpminfo_object id="oval:com.tuxcare.clsa:obj:1785418319003" version="1">
      <red-def:name>alt-python36-pip-wheel</red-def:name>
    </red-def:rpminfo_object>
  </objects>
  <states>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1748352587001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-6.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1748352587002" version="1">
      <red-def:signature_keyid operation="equals">d07bf2a08d50eb66</red-def:signature_keyid>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1749037854001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-7.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1753205878001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-8.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1753804881001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-14.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1754039871001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-16.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1760098218001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-20.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1760369183001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-21.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1762528386001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-13.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1771339135001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-16.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1772111352001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-22.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1772139704001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-17.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1772188508001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-23.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1772446514001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-18.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1772559514001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-19.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1772721745001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-24.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1773240322001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-25.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1776434771001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-20.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1777047108001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-27.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1777390475001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-21.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1777478783001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-29.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1777630510001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-30.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1777637454001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-22.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1778161965001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-23.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1778245330001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-31.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1779278705001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-24.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1779463938001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-32.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1779880402001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-25.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1779887983001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-33.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1780516373001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-28.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1781103532001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-34.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1781521190001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-29.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1782297615001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-30.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1782998840001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-35.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1783343295001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-37.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784298097001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.8.20-19.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784300728001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.9.23-17.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784311073001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.11.15-1.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784312324001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.10.20-1.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784372957001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:58.3.0-3.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784800604001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.10.20-2.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784804478001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-38.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784811769001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.9.23-20.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784815391001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.8.20-21.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784822014001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-31.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784823685001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.11.15-3.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784882920001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.10.20-3.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1784902318001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.10.20-4.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785141727001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.11.15-4.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785148862001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:38.5.2-9.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785171014001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:21.3.1-6.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785171898001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:21.3.1-5.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785173409001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:22.2.1-5.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785228248001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">1:0.37.1-3.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785230640001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:58.3.0-5.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785237053001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:0.37.0-2.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785241961001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:65.6.3-4.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785310634001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:0.37.0-4.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785315201001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:0.31.1-2.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785325771001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:0.37.0-5.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785335543001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:21.3.1-4.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785342083001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.11.15-5.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785403906001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.9.23-24.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785418319001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:20.2.4-6.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785422123001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.9.23-21.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785429417001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.10.20-9.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1785502244001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.11.15-6.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1786468319001" version="1">
      <red-def:evr datatype="evr_string" operation="less than">0:38.5.2-10.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1786541588001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:2.7.18-41.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1786542344001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.8.20-22.el9</red-def:evr>
    </red-def:rpminfo_state>
    <red-def:rpminfo_state id="oval:com.tuxcare.clsa:ste:1786555316001" version="1">
      <red-def:arch datatype="string" operation="equals">x86_64</red-def:arch>
      <red-def:evr datatype="evr_string" operation="less than">0:3.6.15-34.el9</red-def:evr>
    </red-def:rpminfo_state>
  </states>
</oval_definitions>
