[CLSA-2026:1790684420] Fix CVE(s): CVE-2026-19672
Type:
security
Severity:
Moderate
Release date:
2026-09-29 12:20:32 UTC
Description:
* SECURITY UPDATE: tarfile ignored a None result from the extraction filter on the link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in TarFile.makelink_with_filter() and return early when it is None, so a filter that skips a member by returning None is honoured when link extraction falls back to copying the target under the link's own, shallower name instead of the member being extracted anyway (CWE-22). - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination - debian/patches/CVE-2026-19672.patch: collapse ".." components with os.path.normpath() in _get_filtered_attrs() before the containment check, so a member whose name leaves the destination and comes back, such as "../evil/../dest/sub/file", no longer creates the intermediate directories outside it. The containment check looked at the resolved path, which stayed inside, while the directories were created from the name as given (CWE-22). Backport of upstream commit 97688346ada2. - Behaviour change: the "tar" and "data" filters now rewrite such names with os.path.normpath(), which removes internal ".." components and so may change the meaning of a name that traverses symbolic links. - CVE-2026-19672
CVEs fixed:
Updated packages:
  • alt-python313_3.13.15-5_amd64.deb
    sha:7b2b584d970c8e5d20202430da6429ce131f9a20
  • alt-python313-debug_3.13.15-5_amd64.deb
    sha:18cc5fc794a7578533b7000913ca170dab69e181
  • alt-python313-devel_3.13.15-5_amd64.deb
    sha:c9e720afda78f493967bf61d159d79f6db904138
  • alt-python313-idle_3.13.15-5_amd64.deb
    sha:cc48e58ec8d0e6e9146940d3ee4127142d533c5b
  • alt-python313-libs_3.13.15-5_amd64.deb
    sha:b9b672799f816056bbeed78a97fb642b22bb8e73
  • alt-python313-test_3.13.15-5_amd64.deb
    sha:adc967f89ccff6b7a119eb4a960a505c74c2f776
  • alt-python313-tkinter_3.13.15-5_amd64.deb
    sha:62d11ba8f6d6d704dd8632f4de2a8a7f7943c759
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.