Release date:
2026-09-29 08:49:08 UTC
Description:
* SECURITY UPDATE: tarfile ignored a None result from the extraction filter
on the link fallback path
- debian/patches/CVE-2026-87910.patch: keep the result of the first
filter_function() call in TarFile.makelink_with_filter() and return
early when it is None, so a filter that skips a member by returning
None is honoured when link extraction falls back to copying the target
under the link's own, shallower name instead of the member being
extracted anyway (CWE-22).
- CVE-2026-87910
* SECURITY UPDATE: tarfile tar/data filters created directories outside the
destination
- debian/patches/CVE-2026-19672.patch: collapse ".." components with
os.path.normpath() in _get_filtered_attrs() before the containment
check, so a member whose name leaves the destination and comes back,
such as "../evil/../dest/sub/file", no longer creates the intermediate
directories outside it. The containment check looked at the resolved
path, which stayed inside, while the directories were created from the
name as given (CWE-22). Backport of upstream commit 97688346.
- Behaviour change: under the "tar" and "data" filters, member names
containing ".." components are now normalized with os.path.normpath(),
which removes internal ".." components and so may change the meaning of
a name that traverses symbolic links.
- CVE-2026-19672
Updated packages:
-
alt-python312_3.12.14-8_amd64.deb
sha:541d4e5eebee0a341532135ada3e8cf68fa1eb5c
-
alt-python312-debug_3.12.14-8_amd64.deb
sha:e469d71b3350694771cb564a6fe5ad9012be52af
-
alt-python312-devel_3.12.14-8_amd64.deb
sha:e985e3d25aba907454678a1e2c2e79df382b7398
-
alt-python312-idle_3.12.14-8_amd64.deb
sha:ac086673f61c7cb16460428b4f3e45fa663a03ce
-
alt-python312-libs_3.12.14-8_amd64.deb
sha:9662d0d6e988faf1979e84b2250d20f0f8067319
-
alt-python312-test_3.12.14-8_amd64.deb
sha:ecf058c9367277b9d101e48bd46518378138fe10
-
alt-python312-tkinter_3.12.14-8_amd64.deb
sha:d2e1dc28aef0e1cc2e98f3dca4e5ad2e87024ab0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.