Release date:
2026-09-29 17:22:52 UTC
Description:
* SECURITY UPDATE: tarfile ignored a "skip this member" answer from a
custom extraction filter on the hard-link fallback. The CVE-2026-11940
hardening re-validates a link's target under the link's own name before
extracting it as a copy, but makelink_with_filter() threw that call's
return value away and the next line overwrote it with the result of the
ordinary filter call. A filter that returns None - the documented PEP 706
way to say "skip" - was therefore ignored for the re-rooted member, and
the member was extracted anyway at the link's shallower name, exactly the
placement the filter had declined. The bundled "data" and "tar" filters
raise instead of returning None, so only custom filter callables are
affected.
- debian/patches/CVE-2026-87910.patch: backport of cpython
9c17bace90f88dfba6d0e2fe23c8e7ae35f83955 (gh-157265, GH-157266,
GH-157308), the 3.13-branch form of the fix, together with its test
follow-up d9565e54b1fc6d63c5be9afd58114499128fa57b. The two added lines
are upstream's verbatim; only the hunk anchor differs. The upstream test
test_extract_filters_target_none is carried too, minus the @symlink_test
decorator and with os_helper.can_symlink() spelled
support.can_symlink(), neither of which exists in 3.6.
- Applied strictly after CVE-2026-11940.patch in all three packaging
paths: that patch is carried by this package rather than native to
3.6, and it supplies the re-rooted filter call this fix repairs.
Reordering the two would leave this patch nothing to apply against.
- CVE-2026-87910
* SECURITY UPDATE: the tarfile "tar" and "data" extraction filters created
directories outside the destination for a member whose name leaves the
destination and comes back, such as "../evil/../dest/sub/file".
_get_filtered_attrs() decided containment on the resolved path, which for
such a name lands back inside and passes the check, but tarfile creates
the intermediate directories from the name as given and so walked out of
the destination on the way, leaving an attacker-named directory beside it.
Normalizing the name before the check, and writing the normalized form
back into the member attributes, makes the directories that get created
match the path that was validated.
- Behaviour change: the "tar" and "data" filters now rewrite any member
name containing ".." components with os.path.normpath(), which removes
internal ".." components and so may change the meaning of a name that
traverses symbolic links.
- debian/patches/CVE-2026-19672.patch: backport of cpython
97688346ada2df3e5b9c279348862c3d64ab0823 (gh-155999, GH-156000). The
seven added lines and all of their context are upstream's verbatim; the
hunk applies to this tree unchanged. The upstream regression test
test_parent_dir_out_and_back is carried as merged, only re-anchored,
because this tree's test_parent_symlink has no @symlink_test decorator
for the hunk to end on.
- This CVE reaches this package only because the PEP 706 extraction
filters are backported here by CVE-2007-4559.patch and the
realpath(strict=ALLOW_MISSING) containment check by CVE-2026-7774.patch;
upstream 3.6 has no filter machinery at all. The patch is
therefore ordered after every other tarfile-touching patch in all three
packaging paths.
- CVE-2026-19672
* The Misc/NEWS.d fragments of both upstream commits are omitted; this
version ships a single Misc/NEWS file.
Updated packages:
-
alt-python36_3.6.15-48_amd64.deb
sha:eba151d32a16af62e60645da3c52fb917b4467ca
-
alt-python36-debug_3.6.15-48_amd64.deb
sha:95900f979a5b796fd67337e1f49fe605710a35d5
-
alt-python36-devel_3.6.15-48_amd64.deb
sha:20117a3bfb5707a936b8669b31751992210a8a97
-
alt-python36-libs_3.6.15-48_amd64.deb
sha:7d577d601a8f10a3a10a7b748068d3904010e875
-
alt-python36-test_3.6.15-48_amd64.deb
sha:6e34a8c7d093a57e3fc6d67ec8b663d99d8ca602
-
alt-python36-tkinter_3.6.15-48_amd64.deb
sha:f93ee97142a5128bff616ef9b6bba4259beac8b6
-
alt-python36-tools_3.6.15-48_amd64.deb
sha:89c9ecc17093398f4d64a69ace46b3baa274519e
-
alt-python36_3.6.15-48_arm64.deb
sha:e91d762419f1255fb0d748a631289cb7a38622e5
-
alt-python36-debug_3.6.15-48_arm64.deb
sha:9dbc72a48b8ec616fbe2240666779d37d4d3d3ea
-
alt-python36-devel_3.6.15-48_arm64.deb
sha:a739185dfc7567f2a5d654dd09b8ad85d6ff9d62
-
alt-python36-libs_3.6.15-48_arm64.deb
sha:adc4f7cd975e6d2b9afef3409098a8f75ef6786c
-
alt-python36-test_3.6.15-48_arm64.deb
sha:e11b103831749ed63611f32b471a1b79a0a3dacc
-
alt-python36-tkinter_3.6.15-48_arm64.deb
sha:8e5f874045cc361f0a5df2ce8641da66fe5cbf2b
-
alt-python36-tools_3.6.15-48_arm64.deb
sha:e79333561312f863ad4ffeaff242476c6772ef13
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.