[CLSA-2026:1790683934] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 12:12:27 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a member on the hard-link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in makelink_with_filter() and return when it is None. When extracting a hard link falls back to extracting the target member under the link's own name, the CVE-2026-11940 guard re-runs the filter with that substituted name, but only an exception was acted upon. A PEP 706 custom filter signals "skip this member" by returning None rather than raising, so such a filter was silently ignored on this path and the member was extracted anyway, under the very name the filter had just refused. Also carries upstream's test_extract_filters_target_none regression test and the matching adjustment to test_sneaky_hardlink_fallback. The guard being repaired is native to the shipped upstream micro 3.11.16, not a patch of ours - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination for a member name that leaves it and returns - debian/patches/CVE-2026-19672.patch: normalise a member name containing a ".." component in _get_filtered_attrs() before the containment check. The check looks at the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories are created from the name as given, so "evil" was created as a sibling of the destination directory. POSIX only. Also carries upstream's test_parent_dir_out_and_back regression test. Backported from upstream commit 97688346ada2 (gh-155999). Upstream carries this on 3.12 and newer only; the backport pull request for 3.11 is still open, so this is ahead of upstream - Behaviour change: the "tar" and "data" filters now hand back member names containing ".." in os.path.normpath() form; as upstream notes, removing internal ".." components may change what such a name refers to if it traverses a symbolic link - CVE-2026-19672
Updated packages:
  • alt-python311_3.11.16-3_amd64.deb
    sha:e2b1a72ab15ea570e804e44544acfa6f954c4388
  • alt-python311-debug_3.11.16-3_amd64.deb
    sha:6bc6b444c6fece726f1b3b38ff23211e49eefb4d
  • alt-python311-devel_3.11.16-3_amd64.deb
    sha:4e47a656e2f7368f4792ed420bb614e8eb8d39c0
  • alt-python311-idle_3.11.16-3_amd64.deb
    sha:dc07584037707464bb8934793c172c78f87bc2ff
  • alt-python311-libs_3.11.16-3_amd64.deb
    sha:4f09cce891223358fb42aed1e5d712324328628d
  • alt-python311-test_3.11.16-3_amd64.deb
    sha:619be7b8ddd253e1a49c8cb7cb72e5530aec78d8
  • alt-python311-tkinter_3.11.16-3_amd64.deb
    sha:e078b063c01a3e6f046b100806cb1e7454222bcd
  • alt-python311_3.11.16-3_arm64.deb
    sha:6760ead5ed192dbd86fa0849441451e16b941820
  • alt-python311-debug_3.11.16-3_arm64.deb
    sha:2df47ac008503cd1130bd67e014dcd46ef10df3a
  • alt-python311-devel_3.11.16-3_arm64.deb
    sha:a938cb8276b4830fa650b425e427389959f32a74
  • alt-python311-idle_3.11.16-3_arm64.deb
    sha:a474f616e8fb9c820a19fcc20a4389affde1fbd4
  • alt-python311-libs_3.11.16-3_arm64.deb
    sha:d8269c1bf9502be0b9c1b676ec55739a905f0c32
  • alt-python311-test_3.11.16-3_arm64.deb
    sha:35130a29c9ef7b7c0d344dda5fc59f086a27b155
  • alt-python311-tkinter_3.11.16-3_arm64.deb
    sha:37147482309b00a4a102f2a8ff6014b1f9e26bf6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.