Release date:
2026-09-29 11:51:18 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a
member on the hard-link fallback path
- debian/patches/CVE-2026-87910.patch: keep the result of the first
filter_function() call in makelink_with_filter() and return when it is
None. When extracting a hard link falls back to extracting the target
member under the link's own name, the CVE-2026-11940 guard re-runs the
filter with that substituted name, but only an exception was acted
upon. A PEP 706 custom filter signals "skip this member" by returning
None rather than raising, so such a filter was silently ignored on this
path and the member was extracted anyway, under the very name the
filter had just refused. Also carries upstream's
test_extract_filters_target_none regression test and the matching
adjustment to test_sneaky_hardlink_fallback. The guard being repaired
is native to the shipped upstream micro 3.11.16, not a patch of ours
- CVE-2026-87910
* SECURITY UPDATE: tarfile tar/data filters created directories outside the
destination for a member name that leaves it and returns
- debian/patches/CVE-2026-19672.patch: normalise a member name containing
a ".." component in _get_filtered_attrs() before the containment check.
The check looks at the resolved path, which stays inside the
destination for a name such as "../evil/../dest/sub/file", while the
intermediate directories are created from the name as given, so "evil"
was created as a sibling of the destination directory. POSIX only. Also
carries upstream's test_parent_dir_out_and_back regression test.
Backported from upstream commit 97688346ada2 (gh-155999). Upstream
carries this on 3.12 and newer only; the backport pull request for
3.11 is still open, so this is ahead of upstream
- Behaviour change: the "tar" and "data" filters now hand back member
names containing ".." in os.path.normpath() form; as upstream notes,
removing internal ".." components may change what such a name refers
to if it traverses a symbolic link
- CVE-2026-19672
Updated packages:
-
alt-python311_3.11.16-3_amd64.deb
sha:023b6255a30629b043f14263e6668cf967f07367
-
alt-python311-debug_3.11.16-3_amd64.deb
sha:116d1fff03758c31a41167b1b91c80b790a6ee9b
-
alt-python311-devel_3.11.16-3_amd64.deb
sha:d0ddc8c35a644fdf3b672f60937b2db32af30ebe
-
alt-python311-idle_3.11.16-3_amd64.deb
sha:a88e7dc8204a7c48a4a0fae0576de149fbafbfb6
-
alt-python311-libs_3.11.16-3_amd64.deb
sha:c711032c46dc956e2ace3c7bac967f2a2ae7aa54
-
alt-python311-test_3.11.16-3_amd64.deb
sha:59df2d9394abaca5c844da46a04ec6fd036408b1
-
alt-python311-tkinter_3.11.16-3_amd64.deb
sha:59edfbd3fe280f643f7d30963da2d7597ad32f90
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.