Release date:
2026-09-29 11:47:30 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a
member on the hard-link fallback path
- debian/patches/CVE-2026-87910.patch: keep the result of the first
filter_function() call in makelink_with_filter() and return when it is
None. When extracting a hard link falls back to extracting the target
member under the link's own name, the CVE-2026-11940 guard re-runs the
filter with that substituted name, but only an exception was acted
upon. A PEP 706 custom filter signals "skip this member" by returning
None rather than raising, so such a filter was silently ignored on this
path and the member was extracted anyway, under the very name the
filter had just refused. Also carries upstream's
test_extract_filters_target_none regression test and the matching
adjustment to test_sneaky_hardlink_fallback. The guard being repaired
is native to the shipped upstream micro 3.11.16, not a patch of ours
- CVE-2026-87910
* SECURITY UPDATE: tarfile tar/data filters created directories outside the
destination for a member name that leaves it and returns
- debian/patches/CVE-2026-19672.patch: normalise a member name containing
a ".." component in _get_filtered_attrs() before the containment check.
The check looks at the resolved path, which stays inside the
destination for a name such as "../evil/../dest/sub/file", while the
intermediate directories are created from the name as given, so "evil"
was created as a sibling of the destination directory. POSIX only. Also
carries upstream's test_parent_dir_out_and_back regression test.
Backported from upstream commit 97688346ada2 (gh-155999). Upstream
carries this on 3.12 and newer only; the backport pull request for
3.11 is still open, so this is ahead of upstream
- Behaviour change: the "tar" and "data" filters now hand back member
names containing ".." in os.path.normpath() form; as upstream notes,
removing internal ".." components may change what such a name refers
to if it traverses a symbolic link
- CVE-2026-19672
Updated packages:
-
alt-python311_3.11.16-3_amd64.deb
sha:badd3cdcd0ca2997937307d60369a266f220355c
-
alt-python311-debug_3.11.16-3_amd64.deb
sha:116d1fff03758c31a41167b1b91c80b790a6ee9b
-
alt-python311-devel_3.11.16-3_amd64.deb
sha:dec705e637d8acf2e603372c17c608c87fe4bc0e
-
alt-python311-idle_3.11.16-3_amd64.deb
sha:967db27f60e0c162c5b8948b437eaad47c1fc8d7
-
alt-python311-libs_3.11.16-3_amd64.deb
sha:25ba10de8cc7ae3d1dec92761261be92f66d96a8
-
alt-python311-test_3.11.16-3_amd64.deb
sha:9336fce0f3f6540d28e1933092374499f7100ca3
-
alt-python311-tkinter_3.11.16-3_amd64.deb
sha:5f4555fa6fcf00cef8064c36745a4a3030d45636
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.