Release date:
2026-09-29 09:03:10 UTC
Description:
* SECURITY UPDATE: tarfile ignored a None result from the extraction filter
on the link fallback path
- debian/patches/CVE-2026-87910.patch: keep the result of the first
filter_function() call in TarFile.makelink_with_filter() and return
early when it is None, so a filter that skips a member by returning
None is honoured when link extraction falls back to copying the target
under the link's own, shallower name instead of the member being
extracted anyway (CWE-22).
- CVE-2026-87910
* SECURITY UPDATE: tarfile tar/data filters created directories outside the
destination
- debian/patches/CVE-2026-19672.patch: collapse ".." components with
os.path.normpath() in _get_filtered_attrs() before the containment
check, so a member whose name leaves the destination and comes back,
such as "../evil/../dest/sub/file", no longer creates the intermediate
directories outside it. The containment check looked at the resolved
path, which stayed inside, while the directories were created from the
name as given (CWE-22). Backport of upstream commit 97688346ada2.
- Behaviour change: the "tar" and "data" filters now rewrite such names
with os.path.normpath(), which removes internal ".." components and so
may change the meaning of a name that traverses symbolic links.
- CVE-2026-19672
Updated packages:
-
alt-python313_3.13.15-5_amd64.deb
sha:1781d0889996a575d1c672f9755eafddd1750a7e
-
alt-python313-debug_3.13.15-5_amd64.deb
sha:18cc5fc794a7578533b7000913ca170dab69e181
-
alt-python313-devel_3.13.15-5_amd64.deb
sha:1c532d0e5dc534e2c934a92e8a6187b3f38f3e2b
-
alt-python313-idle_3.13.15-5_amd64.deb
sha:5661282aa285c9f76a3704e0ef6c2f4133cdc281
-
alt-python313-libs_3.13.15-5_amd64.deb
sha:8d45c79b41c9539ce29929a3947e81c26a3a0b06
-
alt-python313-test_3.13.15-5_amd64.deb
sha:cfd75adf27fae941b86d1464c80cde79ffbd4d8f
-
alt-python313-tkinter_3.13.15-5_amd64.deb
sha:829813ce055192691ea4b068afed7ec3d28e2000
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.