File _patchinfo of Package patchinfo.42118
<patchinfo incident="42118"> <issue tracker="cve" id="2026-22701"/> <issue tracker="cve" id="2025-68146"/> <issue tracker="bnc" id="1256457">VUL-0: CVE-2026-22701: python-filelock: Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package</issue> <issue tracker="bnc" id="1255244">VUL-0: CVE-2025-68146: python-filelock: TOCTOU race condition may allow local attackers to corrupt or truncate arbitrary user files</issue> <packager>nkrapp</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for python-filelock</summary> <description>This update for python-filelock fixes the following issues: - CVE-2025-68146: TOCTOU race condition may allow local attackers to corrupt or truncate arbitrary user files (bsc#1255244). - CVE-2026-22701: TOCTOU race condition in the SoftFileLock implementation (bsc#1256457). </description> </patchinfo>