[CLSA-2026:1790697526] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 15:58:57 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a member on the hard-link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in makelink_with_filter() and return when it is None. When extracting a hard link falls back to extracting the target member under the link's own name, the CVE-2026-11940 guard re-runs the filter with that substituted name, but only an exception was acted upon. A PEP 706 custom filter signals "skip this member" by returning None rather than raising, so such a filter was silently ignored on this path and the member was extracted anyway, under the very name the filter had just refused. Also carries upstream's test_extract_filters_target_none regression test and the matching adjustment to test_sneaky_hardlink_fallback. The guard being repaired is native to the shipped upstream micro 3.11.16, not a patch of ours - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination for a member name that leaves it and returns - debian/patches/CVE-2026-19672.patch: normalise a member name containing a ".." component in _get_filtered_attrs() before the containment check. The check looks at the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories are created from the name as given, so "evil" was created as a sibling of the destination directory. POSIX only. Also carries upstream's test_parent_dir_out_and_back regression test. Backported from upstream commit 97688346ada2 (gh-155999). Upstream carries this on 3.12 and newer only; the backport pull request for 3.11 is still open, so this is ahead of upstream - Behaviour change: the "tar" and "data" filters now hand back member names containing ".." in os.path.normpath() form; as upstream notes, removing internal ".." components may change what such a name refers to if it traverses a symbolic link - CVE-2026-19672
Updated packages:
  • alt-python311_3.11.16-3_amd64.deb
    sha:2f789174a061d6a3508bb699ce2be24004b004df
  • alt-python311-debug_3.11.16-3_amd64.deb
    sha:6bc6b444c6fece726f1b3b38ff23211e49eefb4d
  • alt-python311-devel_3.11.16-3_amd64.deb
    sha:6a1fc4fd03cb8ade2178f1056e35d65930866f13
  • alt-python311-idle_3.11.16-3_amd64.deb
    sha:f0dc34027779fe1364adb7d563372b69501d01a9
  • alt-python311-libs_3.11.16-3_amd64.deb
    sha:732a549f153d2a2f5dc577fcc9fd123c8efaa16a
  • alt-python311-test_3.11.16-3_amd64.deb
    sha:546bd46f8f48004b4f7ad72d6220bd1e27d71bfc
  • alt-python311-tkinter_3.11.16-3_amd64.deb
    sha:3fadb011fa0bc844c7768944d92848378ef30877
  • alt-python311_3.11.16-3_arm64.deb
    sha:8521a8aa4f622409ffa7b4f519d058529005dee9
  • alt-python311-debug_3.11.16-3_arm64.deb
    sha:2df47ac008503cd1130bd67e014dcd46ef10df3a
  • alt-python311-devel_3.11.16-3_arm64.deb
    sha:6dc0c9a5e2f2c8eee8ffaaaeaa2eccdaa3e60ca6
  • alt-python311-idle_3.11.16-3_arm64.deb
    sha:7ed701b83cdc732a97c5849fd7e5aba9d52a54f9
  • alt-python311-libs_3.11.16-3_arm64.deb
    sha:834e7274ba3da2d3b5178168dfdb6aff0a657254
  • alt-python311-test_3.11.16-3_arm64.deb
    sha:172ac6698d58e70e47b1eff97da5089cfd2f88fa
  • alt-python311-tkinter_3.11.16-3_arm64.deb
    sha:a3533d260c9877e4980366abc78e827cd313e191
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.