[CLSA-2026:1790701337] alt-python314: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-29 17:02:29 UTC
Description:
- SECURITY UPDATE: tarfile: honor a None result from the link-fallback filter call (CVE-2026-87910). When a hard link cannot be created, tarfile extracts the target member under the link's name and runs the filter on that renamed member first; a None result (skip this member) from that call was discarded, so a filter that refused the name was overridden and the member extracted anyway. That result is now honored before the second filter call. - SECURITY UPDATE: tarfile: normalize member names that leave the destination and come back (CVE-2026-19672, upstream commit 97688346). The tar and data filters checked containment on the resolved path, but directories are created from the name as given, so a name like '../evil/../dest/sub/file' passed the check while creating '../evil' outside the destination. Such names are now normalized before the check, so the directories created are the ones that were validated. Normalization drops internal '..' components and may change the meaning of a name that traverses symbolic links.
Updated packages:
  • alt-python314-3.14.7-2.el7.x86_64.rpm
    sha:3ff43d46cc77fd24b441ce33e61fad49c8bc2cd921f2115fafd1622309fa81b3
  • alt-python314-debug-3.14.7-2.el7.x86_64.rpm
    sha:ff0278e53bcc405d6ad1a8edf771348bbfb1980705bf8f804da374829c1c6bf0
  • alt-python314-devel-3.14.7-2.el7.x86_64.rpm
    sha:b86e960753439d526eecb1a54d9f6ba284aa2a726d8b9c6ca9a28957042c595e
  • alt-python314-idle-3.14.7-2.el7.x86_64.rpm
    sha:dfb21d27888624d50485c733d3c92d52898d7760a8007c9d34a829e464af11f9
  • alt-python314-libs-3.14.7-2.el7.x86_64.rpm
    sha:8c0a66a5662515e16bf84b31b679aee60fb6baa28314fa721a80adaae5cd3532
  • alt-python314-test-3.14.7-2.el7.x86_64.rpm
    sha:e6ae268b4fa3c62d5d5ecb4866383b12b3dfafb36e768de6bdecd1aed2029a08
  • alt-python314-tkinter-3.14.7-2.el7.x86_64.rpm
    sha:c6e3688608c1e878729a35236bd6b2e263ffde0940420d0f1f6225d69749a45e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.