[CLSA-2026:1790670062] alt-python310: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-29 08:21:16 UTC
Description:
- CVE-2026-87910: honour a None result from the extraction filter on tarfile's hard-link fallback path. makelink_with_filter() discarded the result of the CVE-2026-11940 re-validation call and acted only on its exceptions, so a PEP 706 custom filter that skips a member by returning None was ignored and the member was extracted anyway, under the link's name. Carries upstream's test_extract_filters_target_none. The guard being repaired is native to upstream 3.10.21, not a patch of ours - CVE-2026-19672: normalise a tarfile member name containing ".." before the containment check in _get_filtered_attrs(). The "tar" and "data" filters validated the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories were created from the name as given and landed outside it. POSIX only. Carries upstream's test_parent_dir_out_and_back as merged. Backported from upstream commit 97688346 (gh-155999). Upstream has this on 3.12+ only; the 3.10 backport pull request is still open
Updated packages:
  • alt-python310-3.10.21-3.el7.x86_64.rpm
    sha:18850a3caa0eaabfe8196de212bf2f0f99de2f5c402ed805c1af4ee5af1466d4
  • alt-python310-debug-3.10.21-3.el7.x86_64.rpm
    sha:8c7eeaed7824ce5a2aa5bf8bec075451cea3ac5e512c04fb04d4c41104a72283
  • alt-python310-devel-3.10.21-3.el7.x86_64.rpm
    sha:c1a3bedaa424650570d297953371892abbcad5897274a6149badce928bdbae62
  • alt-python310-idle-3.10.21-3.el7.x86_64.rpm
    sha:c6e42a14b132a2e0ffdf1ec1b25cab88c5d279dcffcc68de2f7c0bfcf41e2311
  • alt-python310-libs-3.10.21-3.el7.x86_64.rpm
    sha:6a1d84b38ea089bed3c0183350e09a103534f8c1655d226cc12eaf364df9bbab
  • alt-python310-test-3.10.21-3.el7.x86_64.rpm
    sha:ed6f19acab2bea2813e481f73e30b7b1a20e6cb46029003812fd8050262b4b1c
  • alt-python310-tkinter-3.10.21-3.el7.x86_64.rpm
    sha:3ce6c3c2710aa5b4f5615985911fdd144ac71df64889a1957cef9ad6da90a43a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.