[CLSA-2026:1790670560] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 08:29:34 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a member on the hard-link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in makelink_with_filter() and return when it is None. When extracting a hard link falls back to extracting the target member under the link's own name, the CVE-2026-11940 guard re-runs the filter with that substituted name, but only an exception was acted upon. A PEP 706 custom filter signals "skip this member" by returning None rather than raising, so such a filter was silently ignored on this path and the member was extracted anyway, under the very name the filter had just refused. Also carries upstream's test_extract_filters_target_none regression test and the matching adjustment to test_sneaky_hardlink_fallback. The guard being repaired is native to the shipped upstream micro 3.10.21, not a patch of ours - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination for a member name that leaves it and returns - debian/patches/CVE-2026-19672.patch: normalise a member name containing a ".." component in _get_filtered_attrs() before the containment check. The check looks at the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories are created from the name as given, so "evil" was created as a sibling of the destination directory. POSIX only. Also carries upstream's test_parent_dir_out_and_back regression test, as merged. Backported from upstream commit 97688346 (gh-155999, GH-156000). Behaviour change: the "tar" and "data" filters now rewrite such a member name with os.path.normpath(), which drops internal ".." components and so may change the meaning of a name that traverses symbolic links. Upstream carries this on 3.12 and newer only; the backport pull request for 3.10 is still open, so this is ahead of upstream - CVE-2026-19672
Updated packages:
  • alt-python310_3.10.21-3_amd64.deb
    sha:71f7cfa219bc8ea19525c7158590fead1d254da9
  • alt-python310-debug_3.10.21-3_amd64.deb
    sha:d2d03426ba5869867e93a416fae78b3b225d9914
  • alt-python310-devel_3.10.21-3_amd64.deb
    sha:d006e9843179a7c9ae6dedad5a552392627650f0
  • alt-python310-idle_3.10.21-3_amd64.deb
    sha:47256425c2d719a511b2f4549efebb11237a0559
  • alt-python310-libs_3.10.21-3_amd64.deb
    sha:2ba62dd4660d0e7cb55b990731a5f24b3198e585
  • alt-python310-test_3.10.21-3_amd64.deb
    sha:a61a1d315b50a41dff0f847ffdbcddcb4bb5fed1
  • alt-python310-tkinter_3.10.21-3_amd64.deb
    sha:fe878b7ff4cd85bfd71b06442a526557c87bc1cb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.