Release date:
2026-09-29 11:59:36 UTC
Description:
* SECURITY UPDATE: tarfile ignored a None result from the extraction filter
on the link fallback path
- debian/patches/CVE-2026-87910.patch: keep the result of the first
filter_function() call in TarFile.makelink_with_filter() and return
early when it is None, so a filter that skips a member by returning
None is honoured when link extraction falls back to copying the target
under the link's own, shallower name instead of the member being
extracted anyway (CWE-22).
- CVE-2026-87910
* SECURITY UPDATE: tarfile tar/data filters created directories outside the
destination
- debian/patches/CVE-2026-19672.patch: collapse ".." components with
os.path.normpath() in _get_filtered_attrs() before the containment
check, so a member whose name leaves the destination and comes back,
such as "../evil/../dest/sub/file", no longer creates the intermediate
directories outside it. The containment check looked at the resolved
path, which stayed inside, while the directories were created from the
name as given (CWE-22). Backport of upstream commit 97688346.
- Behaviour change: under the "tar" and "data" filters, member names
containing ".." components are now normalized with os.path.normpath(),
which removes internal ".." components and so may change the meaning of
a name that traverses symbolic links.
- CVE-2026-19672
Updated packages:
-
alt-python312_3.12.14-8_amd64.deb
sha:9fb51c196ac50da01df25b3572eb4520cef631ff
-
alt-python312-debug_3.12.14-8_amd64.deb
sha:e469d71b3350694771cb564a6fe5ad9012be52af
-
alt-python312-devel_3.12.14-8_amd64.deb
sha:7a36e3246b53096b93dc4bbc1c1b5e101ff0c7a2
-
alt-python312-idle_3.12.14-8_amd64.deb
sha:50590bab580315f81d945f966039de5d4033f202
-
alt-python312-libs_3.12.14-8_amd64.deb
sha:431c2829c18b3bdaa7c8caba714f7337630df458
-
alt-python312-test_3.12.14-8_amd64.deb
sha:74869279feaa80e42331a9a0ba2bce1f9c861ad2
-
alt-python312-tkinter_3.12.14-8_amd64.deb
sha:e84ad0fcf6feebbd311d3228cc4da7b040dd0605
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.