[CLSA-2026:1790680512] alt-python311: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-29 11:15:24 UTC
Description:
- CVE-2026-87910: honour a None result from the extraction filter on tarfile's hard-link fallback path. makelink_with_filter() discarded the result of the CVE-2026-11940 re-validation call and acted only on its exceptions, so a PEP 706 custom filter that skips a member by returning None was ignored and the member was extracted anyway, under the link's name. Carries upstream's test_extract_filters_target_none. The guard being repaired is native to upstream 3.11.16, not a patch of ours - CVE-2026-19672: normalise a tarfile member name containing ".." before the containment check in _get_filtered_attrs(). The "tar" and "data" filters validated the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories were created from the name as given and landed outside it. POSIX only. Carries upstream's test_parent_dir_out_and_back. Backported from upstream commit 97688346ada2 (gh-155999). Upstream has this on 3.12+ only; the 3.11 backport pull request is still open
Updated packages:
  • alt-python311-3.11.16-3.el10.x86_64.rpm
    sha:b33a32d6790be5d28060a5a8a2fa6cdd7474b5572e74380c113a4631bf064e21
  • alt-python311-debug-3.11.16-3.el10.x86_64.rpm
    sha:15b7b2a8ea0e15c299cbcc659b1594120ed3a03af364057b14d8208833c72c5a
  • alt-python311-devel-3.11.16-3.el10.x86_64.rpm
    sha:604bfa5e4f908d76d96ac822f17e5e2ff1eace01a0480560d68b6a7150db52e6
  • alt-python311-idle-3.11.16-3.el10.x86_64.rpm
    sha:ee7bf1c385d179a00f5b5387eb6825e42a2744b6ad94114328dea8e57943a84a
  • alt-python311-libs-3.11.16-3.el10.x86_64.rpm
    sha:25b679489111856eb4920d88130b87ab3806d50cf7b5610f1398e0d7c275d0b2
  • alt-python311-test-3.11.16-3.el10.x86_64.rpm
    sha:6e2dee3e8ea61fda5e9736254e0f05431d9b011820e1acc5cd74cc6d07a5f02f
  • alt-python311-tkinter-3.11.16-3.el10.x86_64.rpm
    sha:8cef9b3ec7926ced727f35756295082e2e4da87b7f8893126e491dcbbfd989db
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.