Release date:
2026-09-29 17:31:16 UTC
Description:
* SECURITY UPDATE: tarfile ignored a filter's None ("skip this member")
answer in the hard-link extraction fallback (CWE-59, link following). The
guard CVE-2026-11940 added to TarFile.makelink_with_filter() re-runs the
filter on the referenced member re-rooted at the link's own, shallower
name before the fallback extracts it there, but it only reacted to the
exceptions that extra call could raise and discarded its return value. A
PEP 706 filter is also allowed to return None to mean "skip this member",
and that answer was ignored: the second call, made with the member's own
name, still succeeded and the member was written at the link's path
anyway. A custom filter that downgrades FilterError to None - the
documented way to skip unsafe members instead of aborting the whole
extraction - therefore did not stop the escape CVE-2026-11940 was meant
to close. Reproduced on the patched 3.8.20 tree with a two-member archive
('a/b/s' symlink -> '../escape', 'q' hard link -> 'a/b/s') extracted with
a filter returning None on FilterError: before the fix dest/q is
materialised as a symlink to '../escape', whose body points outside the
destination; after it, 'q' is skipped and only a/b/s is extracted.
- debian/patches/CVE-2026-87910.patch: backport of cpython
9c17bace90f88dfba6d0e2fe23c8e7ae35f83955 (gh-157265, GH-157266,
GH-157308, squashing the test follow-up GH-157334), which keeps the
first filter call's result and returns early when it is None, plus its
regression test test_extract_filters_target_none in
Lib/test/test_tarfile.py. Applied after CVE-2026-11940.patch, whose
guard it fixes; the two must not be separated or reordered.
- CVE-2026-87910
* SECURITY UPDATE: tarfile 'tar'/'data' extraction filters created
directories outside the destination for a member whose name leaves the
destination and comes back (CWE-22, path traversal). _get_filtered_attrs()
checks containment by resolving the member name against the destination
and comparing with os.path.commonpath(); a name such as
'../evil/../dest/sub/file' resolves back inside and passes the check, but
the intermediate directories are created from the name as given and walk
out of the destination on the way. Extracting an untrusted archive into a
scratch directory therefore left attacker-chosen directories next to it,
under the very filters meant to prevent that. Reproduced on the patched
3.8.20 tree with a one-member archive named
'../escaped.evil/../dest/sub/file' extracted into outerdir/dest: before
the fix outerdir/escaped.evil is created under both filter='data' and
filter='tar'; after it nothing is created outside the destination and
dest/sub/file still holds its content. POSIX only.
- debian/patches/CVE-2026-19672.patch: backport of cpython
97688346ada2df3e5b9c279348862c3d64ab0823 (gh-155999, GH-156000), which
normalizes a member name containing a '..' component before the
containment check so the directories actually created match the path
that was validated, plus its regression test
test_parent_dir_out_and_back in Lib/test/test_tarfile.py. Applied after
CVE-2026-87910.patch.
- Behaviour change: under the 'tar' and 'data' filters a member name
containing '..' is now normalized with os.path.normpath(), which removes
internal '..' components and may change the meaning of the name if it
traverses symbolic links.
- CVE-2026-19672
Updated packages:
-
alt-python38_3.8.20-30_amd64.deb
sha:f5b682333e53aa7c51b0b8b52279e93d7eb63822
-
alt-python38-debug_3.8.20-30_amd64.deb
sha:2f53d8a784277f2fd6d1877f186b18afcea23670
-
alt-python38-devel_3.8.20-30_amd64.deb
sha:faa349ac1ae570f097880732ed4e65572d33d3eb
-
alt-python38-idle_3.8.20-30_amd64.deb
sha:2df5b3fe101c796e2bbf83aa2472a101c3fdca56
-
alt-python38-libs_3.8.20-30_amd64.deb
sha:48b74ffdff44b5507bd2ae5b16da0abbb449f73f
-
alt-python38-test_3.8.20-30_amd64.deb
sha:4c32d94269335b08c05d6b10c6804d6db1d34962
-
alt-python38-tkinter_3.8.20-30_amd64.deb
sha:80b8310b1ee5456a722a3dc6f18914869c44e585
-
alt-python38_3.8.20-30_arm64.deb
sha:a922b2d9519d337434d6c7b9f902bff81cdc82f4
-
alt-python38-debug_3.8.20-30_arm64.deb
sha:77ce411fba86ba20de91c57db4b4d62214ab0a98
-
alt-python38-devel_3.8.20-30_arm64.deb
sha:cb44b6876c5b6b5f665e511a6c36fbbf38f7f886
-
alt-python38-idle_3.8.20-30_arm64.deb
sha:32a7824eb4b8f238c85dee844fde1d6821ee738a
-
alt-python38-libs_3.8.20-30_arm64.deb
sha:a4f09afe65dad97ab61182cdc08fcd218f275461
-
alt-python38-test_3.8.20-30_arm64.deb
sha:b2ac752fb005942ea28af63cec859eeb35a0cdb3
-
alt-python38-tkinter_3.8.20-30_arm64.deb
sha:ab4e65d8eee0fac02509b79ae182659cc1ae25d1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.