Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-71176

Опубликовано: 22 янв. 2026
Источник: debian

Описание

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pytestunfixedpackage

Примечания

  • https://github.com/pytest-dev/pytest/issues/13669

  • https://www.openwall.com/lists/oss-security/2026/01/21/5

  • Neutralised by kernel hardening (fs.protected_symlinks = 1)

Связанные уязвимости

CVSS3: 6.8
ubuntu
2 месяца назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
redhat
2 месяца назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
nvd
2 месяца назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
github
2 месяца назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.