[CLSA-2026:1790682666] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 11:51:18 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a member on the hard-link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in makelink_with_filter() and return when it is None. When extracting a hard link falls back to extracting the target member under the link's own name, the CVE-2026-11940 guard re-runs the filter with that substituted name, but only an exception was acted upon. A PEP 706 custom filter signals "skip this member" by returning None rather than raising, so such a filter was silently ignored on this path and the member was extracted anyway, under the very name the filter had just refused. Also carries upstream's test_extract_filters_target_none regression test and the matching adjustment to test_sneaky_hardlink_fallback. The guard being repaired is native to the shipped upstream micro 3.11.16, not a patch of ours - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination for a member name that leaves it and returns - debian/patches/CVE-2026-19672.patch: normalise a member name containing a ".." component in _get_filtered_attrs() before the containment check. The check looks at the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories are created from the name as given, so "evil" was created as a sibling of the destination directory. POSIX only. Also carries upstream's test_parent_dir_out_and_back regression test. Backported from upstream commit 97688346ada2 (gh-155999). Upstream carries this on 3.12 and newer only; the backport pull request for 3.11 is still open, so this is ahead of upstream - Behaviour change: the "tar" and "data" filters now hand back member names containing ".." in os.path.normpath() form; as upstream notes, removing internal ".." components may change what such a name refers to if it traverses a symbolic link - CVE-2026-19672
Updated packages:
  • alt-python311_3.11.16-3_amd64.deb
    sha:023b6255a30629b043f14263e6668cf967f07367
  • alt-python311-debug_3.11.16-3_amd64.deb
    sha:116d1fff03758c31a41167b1b91c80b790a6ee9b
  • alt-python311-devel_3.11.16-3_amd64.deb
    sha:d0ddc8c35a644fdf3b672f60937b2db32af30ebe
  • alt-python311-idle_3.11.16-3_amd64.deb
    sha:a88e7dc8204a7c48a4a0fae0576de149fbafbfb6
  • alt-python311-libs_3.11.16-3_amd64.deb
    sha:c711032c46dc956e2ace3c7bac967f2a2ae7aa54
  • alt-python311-test_3.11.16-3_amd64.deb
    sha:59df2d9394abaca5c844da46a04ec6fd036408b1
  • alt-python311-tkinter_3.11.16-3_amd64.deb
    sha:59edfbd3fe280f643f7d30963da2d7597ad32f90
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.