[CLSA-2026:1790672578] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 09:03:10 UTC
Description:
* SECURITY UPDATE: tarfile ignored a None result from the extraction filter on the link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in TarFile.makelink_with_filter() and return early when it is None, so a filter that skips a member by returning None is honoured when link extraction falls back to copying the target under the link's own, shallower name instead of the member being extracted anyway (CWE-22). - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination - debian/patches/CVE-2026-19672.patch: collapse ".." components with os.path.normpath() in _get_filtered_attrs() before the containment check, so a member whose name leaves the destination and comes back, such as "../evil/../dest/sub/file", no longer creates the intermediate directories outside it. The containment check looked at the resolved path, which stayed inside, while the directories were created from the name as given (CWE-22). Backport of upstream commit 97688346ada2. - Behaviour change: the "tar" and "data" filters now rewrite such names with os.path.normpath(), which removes internal ".." components and so may change the meaning of a name that traverses symbolic links. - CVE-2026-19672
Updated packages:
  • alt-python313_3.13.15-5_amd64.deb
    sha:1781d0889996a575d1c672f9755eafddd1750a7e
  • alt-python313-debug_3.13.15-5_amd64.deb
    sha:18cc5fc794a7578533b7000913ca170dab69e181
  • alt-python313-devel_3.13.15-5_amd64.deb
    sha:1c532d0e5dc534e2c934a92e8a6187b3f38f3e2b
  • alt-python313-idle_3.13.15-5_amd64.deb
    sha:5661282aa285c9f76a3704e0ef6c2f4133cdc281
  • alt-python313-libs_3.13.15-5_amd64.deb
    sha:8d45c79b41c9539ce29929a3947e81c26a3a0b06
  • alt-python313-test_3.13.15-5_amd64.deb
    sha:cfd75adf27fae941b86d1464c80cde79ffbd4d8f
  • alt-python313-tkinter_3.13.15-5_amd64.deb
    sha:829813ce055192691ea4b068afed7ec3d28e2000
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.