CVE-2025-71176

NameCVE-2025-71176
Descriptionpytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pytest (PTS)bullseye6.0.2-2vulnerable
bookworm7.2.1-2vulnerable
trixie8.3.5-2vulnerable
forky, sid9.0.2-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pytestsource(unstable)(unfixed)unimportant

Notes

https://github.com/pytest-dev/pytest/issues/13669
https://www.openwall.com/lists/oss-security/2026/01/21/5
Neutralised by kernel hardening (fs.protected_symlinks = 1)

Search for package or bug name: Reporting problems