[CLSA-2026:1790673952] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 09:26:03 UTC
Description:
* SECURITY UPDATE: tarfile ignored a "skip this member" answer from a custom extraction filter on the hard-link fallback. The CVE-2026-11940 hardening re-validates a link's target under the link's own name before extracting it as a copy, but makelink_with_filter() threw that call's return value away and the next line overwrote it with the result of the ordinary filter call. A filter that returns None - the documented PEP 706 way to say "skip" - was therefore ignored for the re-rooted member, and the member was extracted anyway at the link's shallower name, exactly the placement the filter had declined. The bundled "data" and "tar" filters raise instead of returning None, so only custom filter callables are affected. - debian/patches/CVE-2026-87910.patch: backport of cpython 9c17bace90f88dfba6d0e2fe23c8e7ae35f83955 (gh-157265, GH-157266, GH-157308), the 3.13-branch form of the fix, together with its test follow-up d9565e54b1fc6d63c5be9afd58114499128fa57b. The two added lines are upstream's verbatim; only the hunk anchor differs. The upstream test test_extract_filters_target_none is carried too, minus the @symlink_test decorator and with os_helper.can_symlink() spelled support.can_symlink(), neither of which exists in 3.6. - Applied strictly after CVE-2026-11940.patch in all three packaging paths: that patch is carried by this package rather than native to 3.6, and it supplies the re-rooted filter call this fix repairs. Reordering the two would leave this patch nothing to apply against. - CVE-2026-87910 * SECURITY UPDATE: the tarfile "tar" and "data" extraction filters created directories outside the destination for a member whose name leaves the destination and comes back, such as "../evil/../dest/sub/file". _get_filtered_attrs() decided containment on the resolved path, which for such a name lands back inside and passes the check, but tarfile creates the intermediate directories from the name as given and so walked out of the destination on the way, leaving an attacker-named directory beside it. Normalizing the name before the check, and writing the normalized form back into the member attributes, makes the directories that get created match the path that was validated. - Behaviour change: the "tar" and "data" filters now rewrite any member name containing ".." components with os.path.normpath(), which removes internal ".." components and so may change the meaning of a name that traverses symbolic links. - debian/patches/CVE-2026-19672.patch: backport of cpython 97688346ada2df3e5b9c279348862c3d64ab0823 (gh-155999, GH-156000). The seven added lines and all of their context are upstream's verbatim; the hunk applies to this tree unchanged. The upstream regression test test_parent_dir_out_and_back is carried as merged, only re-anchored, because this tree's test_parent_symlink has no @symlink_test decorator for the hunk to end on. - This CVE reaches this package only because the PEP 706 extraction filters are backported here by CVE-2007-4559.patch and the realpath(strict=ALLOW_MISSING) containment check by CVE-2026-7774.patch; upstream 3.6 has no filter machinery at all. The patch is therefore ordered after every other tarfile-touching patch in all three packaging paths. - CVE-2026-19672 * The Misc/NEWS.d fragments of both upstream commits are omitted; this version ships a single Misc/NEWS file.
Updated packages:
  • alt-python36_3.6.15-48_amd64.deb
    sha:37ddd1c163cad329ee548a0926db1ab2c942b1d0
  • alt-python36-debug_3.6.15-48_amd64.deb
    sha:51f33c409af1d41d468becc6e7871fd1b8573d0e
  • alt-python36-devel_3.6.15-48_amd64.deb
    sha:5da1be0164dd127c3eb7fe811ca384822ae93ae0
  • alt-python36-libs_3.6.15-48_amd64.deb
    sha:7c82ef4fb4a86b3887c90ba0a01d4728e639ffaa
  • alt-python36-test_3.6.15-48_amd64.deb
    sha:ccdeb73aa3bb993a901320d5b6baf1ccea909de4
  • alt-python36-tkinter_3.6.15-48_amd64.deb
    sha:17d3a2c7d2508f81983b6c28bebeb63f2bf87442
  • alt-python36-tools_3.6.15-48_amd64.deb
    sha:a995263d05e267a39c3f0b50896357f1a78d578d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.