[CLSA-2026:1790693348] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 14:49:21 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a member on the hard-link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in makelink_with_filter() and return when it is None. When extracting a hard link falls back to extracting the target member under the link's own name, the CVE-2026-11940 guard re-runs the filter with that substituted name, but only an exception was acted upon. A PEP 706 custom filter signals "skip this member" by returning None rather than raising, so such a filter was silently ignored on this path and the member was extracted anyway, under the very name the filter had just refused. Also carries upstream's test_extract_filters_target_none regression test and the matching adjustment to test_sneaky_hardlink_fallback. The guard being repaired is native to the shipped upstream micro 3.10.21, not a patch of ours - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination for a member name that leaves it and returns - debian/patches/CVE-2026-19672.patch: normalise a member name containing a ".." component in _get_filtered_attrs() before the containment check. The check looks at the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories are created from the name as given, so "evil" was created as a sibling of the destination directory. POSIX only. Also carries upstream's test_parent_dir_out_and_back regression test, as merged. Backported from upstream commit 97688346 (gh-155999, GH-156000). Behaviour change: the "tar" and "data" filters now rewrite such a member name with os.path.normpath(), which drops internal ".." components and so may change the meaning of a name that traverses symbolic links. Upstream carries this on 3.12 and newer only; the backport pull request for 3.10 is still open, so this is ahead of upstream - CVE-2026-19672
Updated packages:
  • alt-python310_3.10.21-3_amd64.deb
    sha:ca0502aad46c343e19407085316d84f6a12fb317
  • alt-python310-debug_3.10.21-3_amd64.deb
    sha:d2d03426ba5869867e93a416fae78b3b225d9914
  • alt-python310-devel_3.10.21-3_amd64.deb
    sha:def9fa694a241ac191c1d7e493a2f22dc18ceed5
  • alt-python310-idle_3.10.21-3_amd64.deb
    sha:400c208a4c58db4186c504f4ce46a3b3d027b95b
  • alt-python310-libs_3.10.21-3_amd64.deb
    sha:247055b583b33c30357cb6f655319a875843943e
  • alt-python310-test_3.10.21-3_amd64.deb
    sha:318a51dbe0da64d5e36ca01d78770f0bd20d2551
  • alt-python310-tkinter_3.10.21-3_amd64.deb
    sha:c6048497ebfb8e6796f7718e417af1726226e1c8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.