[CLSA-2026:1790691946] alt-python38: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-29 14:25:59 UTC
Description:
- CVE-2026-87910: tarfile ignored a filter's None ("skip this member") answer in the hard-link extraction fallback (CWE-59). The guard CVE-2026-11940 added to TarFile.makelink_with_filter() re-runs the filter on the referenced member re-rooted at the link's own, shallower name, but only reacted to the exceptions that extra call could raise and discarded its return value. A PEP 706 filter may also return None to mean "skip this member"; that answer was ignored, the second call made with the member's own name still succeeded, and the member was written at the link's path anyway - so a filter that downgrades FilterError to None did not stop the escape CVE-2026-11940 was meant to close. - debian/patches/CVE-2026-87910.patch: backport of cpython 9c17bace90f88dfba6d0e2fe23c8e7ae35f83955 (gh-157265), which keeps the first filter call's result and returns early when it is None, plus its regression test test_extract_filters_target_none. Applied after CVE-2026-11940.patch, whose guard it fixes; the two must not be separated or reordered. - CVE-2026-19672: tarfile 'tar'/'data' extraction filters created directories outside the destination for a member whose name leaves the destination and comes back (CWE-22). _get_filtered_attrs() checks containment on the resolved path, so a name such as '../evil/../dest/sub/file' passes, but the intermediate directories are created from the name as given and walk out of the destination on the way, leaving attacker-chosen directories next to it. POSIX only. - debian/patches/CVE-2026-19672.patch: backport of cpython 97688346ada2df3e5b9c279348862c3d64ab0823 (gh-155999), which normalizes a member name containing a '..' component before the containment check, plus its regression test test_parent_dir_out_and_back. Applied after CVE-2026-87910.patch. Behaviour change: normalization removes internal '..' components, which may change the meaning of a member name that traverses symbolic links.
Updated packages:
  • alt-python38-3.8.20-28.el7.x86_64.rpm
    sha:d0d81ab14979b6069ea9f62168578d608503336c17ea37f6e89bfecb5d0dbc7f
  • alt-python38-debug-3.8.20-28.el7.x86_64.rpm
    sha:af849f25716f97f6c21a152bc8d3d5b279115da58d277caadbf6652e31cc40f5
  • alt-python38-devel-3.8.20-28.el7.x86_64.rpm
    sha:060157638e4f72fbc3a97ef5f984590d70fc173235bfcfd1ace6a84ac0956e97
  • alt-python38-idle-3.8.20-28.el7.x86_64.rpm
    sha:8a0263ee3768b3bbf631aecad5cd57443a58ea6439154007415852c47f9382a1
  • alt-python38-libs-3.8.20-28.el7.x86_64.rpm
    sha:1b3c82ff7ffc51e38b23badfe1f4f185aa35940a3653e38c0e7d48e99e100dc0
  • alt-python38-test-3.8.20-28.el7.x86_64.rpm
    sha:a2d50a325e98c431c80cbcb56ae5d8009728ebc3935e70ec4de7899d9cd8148e
  • alt-python38-tkinter-3.8.20-28.el7.x86_64.rpm
    sha:2652e2f9302ed26db984d20445074ba3aa1ecb9bdc0340f8b8a532bd66cd6831
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.