[CLSA-2026:1790701066] Fix CVE(s): CVE-2026-19672, CVE-2026-87910
Type:
security
Severity:
Moderate
Release date:
2026-09-29 16:58:16 UTC
Description:
* SECURITY UPDATE: tarfile ignored a custom extraction filter that skips a member on the hard-link fallback path - debian/patches/CVE-2026-87910.patch: keep the result of the first filter_function() call in makelink_with_filter() and return when it is None. When extracting a hard link falls back to extracting the target member under the link's own name, the CVE-2026-11940 guard re-runs the filter with that substituted name, but only an exception was acted upon. A PEP 706 custom filter signals "skip this member" by returning None rather than raising, so such a filter was silently ignored on this path and the member was extracted anyway, under the very name the filter had just refused. Also carries upstream's test_extract_filters_target_none regression test and the matching adjustment to test_sneaky_hardlink_fallback. The guard being repaired is native to the shipped upstream micro 3.10.21, not a patch of ours - CVE-2026-87910 * SECURITY UPDATE: tarfile tar/data filters created directories outside the destination for a member name that leaves it and returns - debian/patches/CVE-2026-19672.patch: normalise a member name containing a ".." component in _get_filtered_attrs() before the containment check. The check looks at the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories are created from the name as given, so "evil" was created as a sibling of the destination directory. POSIX only. Also carries upstream's test_parent_dir_out_and_back regression test, as merged. Backported from upstream commit 97688346 (gh-155999, GH-156000). Behaviour change: the "tar" and "data" filters now rewrite such a member name with os.path.normpath(), which drops internal ".." components and so may change the meaning of a name that traverses symbolic links. Upstream carries this on 3.12 and newer only; the backport pull request for 3.10 is still open, so this is ahead of upstream - CVE-2026-19672
Updated packages:
  • alt-python310_3.10.21-3_amd64.deb
    sha:b30eb9ef4d6674b2fb5d56d8fc336f2cc13f694a
  • alt-python310-debug_3.10.21-3_amd64.deb
    sha:319f59fa285e72421fa74209c3ede28acccbddc2
  • alt-python310-devel_3.10.21-3_amd64.deb
    sha:d5aaf22686cb6801c2f1f02c483415e3b323acf5
  • alt-python310-idle_3.10.21-3_amd64.deb
    sha:a6e392f371e979dd4227ef9a9690cd7bf99631ae
  • alt-python310-libs_3.10.21-3_amd64.deb
    sha:85aac63c262b45ba5206e1a7485293a8129f1ea3
  • alt-python310-test_3.10.21-3_amd64.deb
    sha:8b2039a559e7c2b11d85a0be431d2b9c528ec15f
  • alt-python310-tkinter_3.10.21-3_amd64.deb
    sha:11310b9ed2631643ba2756eb87646aea326a502f
  • alt-python310_3.10.21-3_arm64.deb
    sha:7544e7d29579fe52e73535553c67ea52369f4c73
  • alt-python310-debug_3.10.21-3_arm64.deb
    sha:76349f2373626a02be8cdbf976efd3404fc3ecb7
  • alt-python310-devel_3.10.21-3_arm64.deb
    sha:5cd5cc5fea09cb48d7faf0a8068c2d936edb32a4
  • alt-python310-idle_3.10.21-3_arm64.deb
    sha:8a96d8e74a7f4793441fa017a56c3cf0191431f7
  • alt-python310-libs_3.10.21-3_arm64.deb
    sha:f8ef5e131418cd1e0a9eb311dd42d463a5e56a46
  • alt-python310-test_3.10.21-3_arm64.deb
    sha:3d33de5ed86030a9e1c8b14ed6433ba0ee055143
  • alt-python310-tkinter_3.10.21-3_arm64.deb
    sha:72cefd6012c989887aaab4cf9ea6aa25cdbd043e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.