Release date:
2026-09-29 14:03:23 UTC
Description:
- CVE-2026-87910: keep the result of the first filter_function() call in
tarfile's makelink_with_filter() and return early when it is None, so a
filter that skips a member by returning None is honoured when link
extraction falls back to copying the target under the link's own,
shallower name, instead of the member being extracted anyway. Carries
upstream's test_extract_filters_target_none. The doubled filter call this
fixes is the CVE-2026-11940 guard, which is native in 3.13.15 and is not
carried by a patch of ours
- CVE-2026-19672: collapse ".." components with os.path.normpath() in
tarfile's _get_filtered_attrs() before the containment check, so a member
whose name leaves the destination and comes back, such as
"../evil/../dest/sub/file", no longer creates the intermediate directories
outside the destination under the "tar" and "data" filters. The containment
check looked at the resolved path, which stayed inside, while the
directories were created from the name as given. Backport of upstream
commit 97688346ada2. Carries upstream's test_parent_dir_out_and_back
Updated packages:
-
alt-python313-3.13.15-4.el10.x86_64.rpm
sha:d5423e6fcc3cae706f05e5d40bd046b80888b82f37d3efd4d5d545a2234913a3
-
alt-python313-debug-3.13.15-4.el10.x86_64.rpm
sha:506e6ee95dc5c5afb221198dad056840b6b3985b04d29cc2afe465ac56e27c78
-
alt-python313-devel-3.13.15-4.el10.x86_64.rpm
sha:78bcc10e40d568add89a52059c1eb46800219b4736aa374545e4c571b4e859b4
-
alt-python313-idle-3.13.15-4.el10.x86_64.rpm
sha:6ea4ca80f07a3a4dc79893530db86945ca1cf605854c0ccf1e86e12a2a7b3f76
-
alt-python313-libs-3.13.15-4.el10.x86_64.rpm
sha:e7de04116b55bd0566cfaf4d5fccd0f583ed34fb9812dc3225810e39040583f4
-
alt-python313-test-3.13.15-4.el10.x86_64.rpm
sha:d766de230d56bdd825c89b87b222a5db4800ea4529efb4af5b2390fe24d45475
-
alt-python313-tkinter-3.13.15-4.el10.x86_64.rpm
sha:a1c85f14323cb655e18a3b563ce948730c35bafc6b347e66a729e2f41b18acce
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.