CVE-2025-71176

Updated on 22 Jan 2026

Severity

6.8 Medium severity

Details

CVSS score
6.8
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Overview

About vulnerability

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Details

Affected product:
AlmaLinux 9.2 ESU , pytest , pytest-asyncio
Affected packages:
pytest @ 8.4.2.post1+tuxcare (+3 more)
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Fixes