Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-71176

Опубликовано: 22 янв. 2026
Источник: debian
EPSS Низкий

Описание

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pytestunfixedpackage

Примечания

  • https://github.com/pytest-dev/pytest/issues/13669

  • https://www.openwall.com/lists/oss-security/2026/01/21/5

  • Neutralised by kernel hardening (fs.protected_symlinks = 1)

EPSS

Процентиль: 4%
0.0014
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
7 месяцев назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
redhat
7 месяцев назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
nvd
7 месяцев назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

suse-cvrf
4 месяца назад

Security update for python-pytest

suse-cvrf
3 месяца назад

Security update for python-pytest

EPSS

Процентиль: 4%
0.0014
Низкий