[CLSA-2026:1786680546] alt-python38: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-14 04:09:15 UTC
Description:
- CVE-2026-7774: tarfile: make data_filter validate the normalised link target that is actually written to disk, strip trailing separators from a symlink member's name before resolving its directory, and reject link members that resolve to the destination directory itself, closing path-traversal bypasses of the 'data' extraction filter via crafted link entries (symlinks with empty or directory-like names) - Register TestFtpcpSecurity (CVE-2026-8328) in test_ftplib's test_main so regrtest actually runs the test (fixes an omission in the original backport; no functional change to the CVE fix itself)
Updated packages:
  • alt-python38-3.8.20-24.el8.x86_64.rpm
    sha:89e009ceb7a92d7fc39863e80e5c5f3ed9e5fb375af758d460675975e357a6b3
  • alt-python38-debug-3.8.20-24.el8.x86_64.rpm
    sha:d0fe35cefeb9f9252d02315d44b3dc28440ae22ac8d3565230d399067903e9f5
  • alt-python38-devel-3.8.20-24.el8.x86_64.rpm
    sha:b8451fbf8613158e22ba0bc65108e1cf7406b3ebc95784a7ad094838189ef99d
  • alt-python38-idle-3.8.20-24.el8.x86_64.rpm
    sha:1ad719d50c47b539194f6536fbfd3bed7ea95814807c1f0067d4c7f332cd5e63
  • alt-python38-libs-3.8.20-24.el8.x86_64.rpm
    sha:6769de8b8c45b28ad0e0fb2a6b13e76b03d5563b30791d09f4d8c6e6c7fc96ca
  • alt-python38-test-3.8.20-24.el8.x86_64.rpm
    sha:2c36ce06b0001205dc63c86a450d24a5290daf71e0e353f8293a044e13ef162c
  • alt-python38-tkinter-3.8.20-24.el8.x86_64.rpm
    sha:e26358d1c38ca0ca5ac261288a7aa87798d995c4eaaf7645b094b3cbf382d03e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.