[CLSA-2026:1790682924] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 11:55:37 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a member on the hard-link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in makelink_with_filter() and return when it is None. When extracting a hard link falls back to extracting the target member under the link's own name, the CVE-2026-11940 guard re-runs the filter with that substituted name, but only an exception was acted upon. A PEP 706 custom filter signals "skip this member" by returning None rather than raising, so such a filter was silently ignored on this path and the member was extracted anyway, under the very name the filter had just refused. Also carries upstream's test_extract_filters_target_none regression test and the matching adjustment to test_sneaky_hardlink_fallback. The guard being repaired is native to the shipped upstream micro 3.10.21, not a patch of ours - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination for a member name that leaves it and returns - debian/patches/CVE-2026-19672.patch: normalise a member name containing a ".." component in _get_filtered_attrs() before the containment check. The check looks at the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories are created from the name as given, so "evil" was created as a sibling of the destination directory. POSIX only. Also carries upstream's test_parent_dir_out_and_back regression test, as merged. Backported from upstream commit 97688346 (gh-155999, GH-156000). Behaviour change: the "tar" and "data" filters now rewrite such a member name with os.path.normpath(), which drops internal ".." components and so may change the meaning of a name that traverses symbolic links. Upstream carries this on 3.12 and newer only; the backport pull request for 3.10 is still open, so this is ahead of upstream - CVE-2026-19672
Updated packages:
  • alt-python310_3.10.21-3_amd64.deb
    sha:8ebd76def605c1cf08a7646543fb9f1c83cfe24c
  • alt-python310-debug_3.10.21-3_amd64.deb
    sha:319f59fa285e72421fa74209c3ede28acccbddc2
  • alt-python310-devel_3.10.21-3_amd64.deb
    sha:3d1ccbbe4ff80efa76b7bbd422886f1621b99126
  • alt-python310-idle_3.10.21-3_amd64.deb
    sha:066b1b111b5c5d78319c04c0944078eeee032304
  • alt-python310-libs_3.10.21-3_amd64.deb
    sha:4f9b3e3435fd52e421c7f4b69d22055d1bede94a
  • alt-python310-test_3.10.21-3_amd64.deb
    sha:89619f7badddb7df4c7607f6850a367baf0054f4
  • alt-python310-tkinter_3.10.21-3_amd64.deb
    sha:b25b327475083d876bbc887206bf88b37103046c
  • alt-python310_3.10.21-3_arm64.deb
    sha:f27802844432187fdb163ee722e022d41cfe3e00
  • alt-python310-debug_3.10.21-3_arm64.deb
    sha:76349f2373626a02be8cdbf976efd3404fc3ecb7
  • alt-python310-devel_3.10.21-3_arm64.deb
    sha:0415090391f80f00112d4e9732b187f76c1e3007
  • alt-python310-idle_3.10.21-3_arm64.deb
    sha:a2d26488350e33591d543b4c8c012e3e0db630c3
  • alt-python310-libs_3.10.21-3_arm64.deb
    sha:0a7df4b5bff2c1c3df2318f939f080b5873d9652
  • alt-python310-test_3.10.21-3_arm64.deb
    sha:6d2ee8c29ab82db3157d9ecf8e226cd4244e24b9
  • alt-python310-tkinter_3.10.21-3_arm64.deb
    sha:ae50ad0178218d9703356a12852d08b18ba0a07a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.