[CLSA-2026:1790698808] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 16:20:19 UTC
Description:
* SECURITY UPDATE: tarfile ignored a filter's None ("skip this member") answer in the hard-link extraction fallback (CWE-59, link following). The guard CVE-2026-11940 added to TarFile.makelink_with_filter() re-runs the filter on the referenced member re-rooted at the link's own, shallower name before the fallback extracts it there, but it only reacted to the exceptions that extra call could raise and discarded its return value. A PEP 706 filter is also allowed to return None to mean "skip this member", and that answer was ignored: the second call, made with the member's own name, still succeeded and the member was written at the link's path anyway. A custom filter that downgrades FilterError to None - the documented way to skip unsafe members instead of aborting the whole extraction - therefore did not stop the escape CVE-2026-11940 was meant to close. Reproduced on the patched 3.9.23 tree with a two-member archive ('a/b/s' symlink -> '../escape', 'q' hard link -> 'a/b/s') extracted with a filter returning None on FilterError: before the fix dest/q is materialised as a symlink to '../escape', whose body points outside the destination; after it, 'q' is skipped and only a/b/s is extracted. - debian/patches/CVE-2026-87910.patch: backport of cpython 9c17bace90f88dfba6d0e2fe23c8e7ae35f83955 (gh-157265, GH-157266, GH-157308, squashing the test follow-up GH-157334), which keeps the first filter call's result and returns early when it is None, plus its regression test test_extract_filters_target_none in Lib/test/test_tarfile.py. Applied after CVE-2026-11940.patch, whose guard it fixes; the two must not be separated or reordered. - CVE-2026-87910 * SECURITY UPDATE: tarfile 'tar'/'data' extraction filters created directories outside the destination for a member whose name leaves the destination and comes back (CWE-22, path traversal). _get_filtered_attrs() checks containment by resolving the member name against the destination and comparing with os.path.commonpath(); a name such as '../evil/../dest/sub/file' resolves back inside and passes the check, but the intermediate directories are created from the name as given and walk out of the destination on the way. Extracting an untrusted archive into a scratch directory therefore left attacker-chosen directories next to it, under the very filters meant to prevent that. Reproduced on the patched 3.9.23 tree with a one-member archive named '../escaped.evil/../dest/sub/file' extracted into outerdir/dest: before the fix outerdir/escaped.evil is created under both filter='data' and filter='tar'; after it nothing is created outside the destination and dest/sub/file still holds its content. POSIX only. - debian/patches/CVE-2026-19672.patch: backport of cpython 97688346ada2df3e5b9c279348862c3d64ab0823 (gh-155999, GH-156000), which normalizes a member name containing a '..' component before the containment check so the directories actually created match the path that was validated, plus its regression test test_parent_dir_out_and_back in Lib/test/test_tarfile.py. Applied after CVE-2026-87910.patch. - Behaviour change: the 'tar' and 'data' filters now rewrite such a member name with os.path.normpath(), which removes internal '..' components and so may change the meaning of a name that traverses symbolic links. - CVE-2026-19672
Updated packages:
  • alt-python39_3.9.23-31_amd64.deb
    sha:4a9be0652e5f1e3bfcc6f9c0f368e1d3470546bf
  • alt-python39-debug_3.9.23-31_amd64.deb
    sha:70e85ea5fd561b13c80f872ca466451e69439f85
  • alt-python39-devel_3.9.23-31_amd64.deb
    sha:6a95e378dfe9d139fc8639b1f569e62e3fdaaeca
  • alt-python39-idle_3.9.23-31_amd64.deb
    sha:2c9605396559ba9102e4a3509f417aa96b8ce3ec
  • alt-python39-libs_3.9.23-31_amd64.deb
    sha:b119b00f7b2f17c24ae3225a1025c6bd788b0dc0
  • alt-python39-test_3.9.23-31_amd64.deb
    sha:317a1b1045038263654be7ef4dba1a539fdd296d
  • alt-python39-tkinter_3.9.23-31_amd64.deb
    sha:0898102465bce14349ad3ccad5f44f6ad4c63890
  • alt-python39_3.9.23-31_arm64.deb
    sha:682bc8678398a1492e6d08e03b202f53f2d9d0e1
  • alt-python39-debug_3.9.23-31_arm64.deb
    sha:dc303b2f3fe2d77ea63f5068393f4ec0cbe85628
  • alt-python39-devel_3.9.23-31_arm64.deb
    sha:f33f5348d58cd1e6a0d9f74f9b672dbb5904b439
  • alt-python39-idle_3.9.23-31_arm64.deb
    sha:8482a368f66a1677c22b74592940341e82b32d0d
  • alt-python39-libs_3.9.23-31_arm64.deb
    sha:a2c25b605b551549a908d412aeee1870d55c642b
  • alt-python39-test_3.9.23-31_arm64.deb
    sha:6c44659a72a9cc106e81a34ef908601295bb351d
  • alt-python39-tkinter_3.9.23-31_arm64.deb
    sha:f165f57be080e230eb3601e3cba092a415aedbb7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.