Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: pytest: * python3-pytest-9.0.3-1.hum1 (noarch) * pytest-9.0.3-1.hum1.src (src)
AI Analysis
Technical Summary
CVE-2025-71176 is a vulnerability in pytest packaged by Red Hat that involves insecure handling of temporary directories, specifically the use of predictable directory names under /tmp/pytest-of-{user}. This flaw allows a local attacker to cause denial of service or potentially escalate privileges by manipulating these temporary directories. The vulnerability is classified under CWE-379 (Creation of Temporary File in Directory with Insecure Permissions). Red Hat rates this issue as moderate severity and notes that mitigation options either do not exist or do not meet their criteria for ease of use, applicability, or stability. The vulnerability affects local users executing pytest on affected Red Hat products.
Potential Impact
Local users can exploit this vulnerability to cause denial of service or potentially gain elevated privileges on affected systems. The impact is limited to systems where pytest is installed and executed locally. Confidentiality, integrity, and availability impacts are rated low to moderate by Red Hat, with the primary risk being denial of service or privilege escalation via insecure temporary directory handling.
Mitigation Recommendations
Red Hat currently does not provide an official fix or mitigation that meets their criteria for this vulnerability. Users should monitor Red Hat advisories for future updates. Until a fix is available, limiting local user access and avoiding running pytest in untrusted environments may reduce risk. Customers with a Technical Account Manager (TAM) can consult directly for guidance. No immediate patch is available as per the vendor advisory.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: pytest: * python3-pytest-9.0.3-1.hum1 (noarch) * pytest-9.0.3-1.hum1.src (src)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-71176 is a vulnerability in pytest packaged by Red Hat that involves insecure handling of temporary directories, specifically the use of predictable directory names under /tmp/pytest-of-{user}. This flaw allows a local attacker to cause denial of service or potentially escalate privileges by manipulating these temporary directories. The vulnerability is classified under CWE-379 (Creation of Temporary File in Directory with Insecure Permissions). Red Hat rates this issue as moderate severity and notes that mitigation options either do not exist or do not meet their criteria for ease of use, applicability, or stability. The vulnerability affects local users executing pytest on affected Red Hat products.
Potential Impact
Local users can exploit this vulnerability to cause denial of service or potentially gain elevated privileges on affected systems. The impact is limited to systems where pytest is installed and executed locally. Confidentiality, integrity, and availability impacts are rated low to moderate by Red Hat, with the primary risk being denial of service or privilege escalation via insecure temporary directory handling.
Mitigation Recommendations
Red Hat currently does not provide an official fix or mitigation that meets their criteria for this vulnerability. Users should monitor Red Hat advisories for future updates. Until a fix is available, limiting local user access and avoiding running pytest in untrusted environments may reduce risk. Customers with a Technical Account Manager (TAM) can consult directly for guidance. No immediate patch is available as per the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:8580
- Cve Count
- 1
Threat ID: 6a4049ce27e9c7971982a877
Added to database: 06/27/2026, 22:08:14 UTC
Last enriched: 08/16/2026, 17:36:55 UTC
Last updated: 09/12/2026, 10:01:29 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.