Release date:
2026-09-29 13:39:52 UTC
Description:
- CVE-2026-87910: honour a None result from the extraction filter on
tarfile's hard-link fallback path. makelink_with_filter() discarded the
result of the CVE-2026-11940 re-validation call and acted only on its
exceptions, so a PEP 706 custom filter that skips a member by returning
None was ignored and the member was extracted anyway, under the link's
name. Carries upstream's test_extract_filters_target_none. The guard being
repaired is native to upstream 3.10.21, not a patch of ours
- CVE-2026-19672: normalise a tarfile member name containing ".." before the
containment check in _get_filtered_attrs(). The "tar" and "data" filters
validated the resolved path, which stays inside the destination for a name
such as "../evil/../dest/sub/file", while the intermediate directories were
created from the name as given and landed outside it. POSIX only. Carries
upstream's test_parent_dir_out_and_back as merged. Backported from upstream
commit 97688346 (gh-155999). Upstream has this on 3.12+ only; the 3.10
backport pull request is still open
Updated packages:
-
alt-python310-3.10.21-3.el10.x86_64.rpm
sha:5ec454a5858c4cc7db11fcfc66c8a4068cbf2bdaaa705090209467619d1560c3
-
alt-python310-debug-3.10.21-3.el10.x86_64.rpm
sha:c3a34f93c5c40f4aadb289c336682f67c1342172a2d7469bffb230f3c9001ee8
-
alt-python310-devel-3.10.21-3.el10.x86_64.rpm
sha:4b85973a562472bb6bfdac2ef912218b0c93ac92916041e0c6d8da8c22fe91eb
-
alt-python310-idle-3.10.21-3.el10.x86_64.rpm
sha:f771d51ae96dff64922dbb2433e7cb4b51f07facb18f675e55e8a628148a1fba
-
alt-python310-libs-3.10.21-3.el10.x86_64.rpm
sha:fb0fd818521a0f6e1e656333ce4a7eae07232b0348474a2bb88d88f9e04544ff
-
alt-python310-test-3.10.21-3.el10.x86_64.rpm
sha:54ef5f4ab59fc62764ab00f4a0f499107de594253c2b0c4a5a9623f390b55b9f
-
alt-python310-tkinter-3.10.21-3.el10.x86_64.rpm
sha:52cbb87ff0003f1198023e080789e93e10929366d1d2a76af712753a70bf93f7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.