[CLSA-2026:1786680256] alt-python38: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-14 04:04:26 UTC
Description:
- CVE-2026-7774: tarfile: make data_filter validate the normalised link target that is actually written to disk, strip trailing separators from a symlink member's name before resolving its directory, and reject link members that resolve to the destination directory itself, closing path-traversal bypasses of the 'data' extraction filter via crafted link entries (symlinks with empty or directory-like names) - Register TestFtpcpSecurity (CVE-2026-8328) in test_ftplib's test_main so regrtest actually runs the test (fixes an omission in the original backport; no functional change to the CVE fix itself)
Updated packages:
  • alt-python38-3.8.20-24.el7.x86_64.rpm
    sha:8f9c3b0cc5f13675106b2f4f44e194f63ed0dd983fdd0b2a9b523d0ff901cd8d
  • alt-python38-debug-3.8.20-24.el7.x86_64.rpm
    sha:e3786195ca5a7d224acdb3a4810463a8f426477bd7880f6e1a49445b6dd424c9
  • alt-python38-devel-3.8.20-24.el7.x86_64.rpm
    sha:fb42c97fe83f80c521b0b7b36e12916ef42c6e92be16c4bc389a01fb1c2af237
  • alt-python38-idle-3.8.20-24.el7.x86_64.rpm
    sha:143fc90aeddc1429ac566eb0336ad3938234efd53e265b21fc4aeb2d6d0a0552
  • alt-python38-libs-3.8.20-24.el7.x86_64.rpm
    sha:a8d24a2d75ee452fc002a89834c141418879c21ee09db829cf181ed85beba568
  • alt-python38-test-3.8.20-24.el7.x86_64.rpm
    sha:855067b8bcd38cef80c5674fd46f915ff058755bbba42c2578aafef3e1eab7b2
  • alt-python38-tkinter-3.8.20-24.el7.x86_64.rpm
    sha:08348ffd1e243606242b8393529b6f17a93d5ffa96f50a9bc3aabc1292c260db
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.