Release date:
2026-09-29 09:37:25 UTC
Description:
- CVE-2026-87910: tarfile ignored a filter's None ("skip this member") answer in
the hard-link extraction fallback (CWE-59). The guard CVE-2026-11940 added to
TarFile.makelink_with_filter() re-runs the filter on the referenced member
re-rooted at the link's own, shallower name, but only reacted to the exceptions
that extra call could raise and discarded its return value. A PEP 706 filter may
also return None to mean "skip this member"; that answer was ignored, the second
call made with the member's own name still succeeded, and the member was written
at the link's path anyway - so a filter that downgrades FilterError to None did
not stop the escape CVE-2026-11940 was meant to close.
- debian/patches/CVE-2026-87910.patch: backport of cpython
9c17bace90f88dfba6d0e2fe23c8e7ae35f83955 (gh-157265), which keeps the first
filter call's result and returns early when it is None, plus its regression test
test_extract_filters_target_none. Applied after CVE-2026-11940.patch, whose
guard it fixes; the two must not be separated or reordered.
- CVE-2026-19672: tarfile 'tar'/'data' extraction filters created directories
outside the destination for a member whose name leaves the destination and comes
back (CWE-22). _get_filtered_attrs() checks containment on the resolved path, so
a name such as '../evil/../dest/sub/file' passes, but the intermediate
directories are created from the name as given and walk out of the destination
on the way, leaving attacker-chosen directories next to it. POSIX only.
- debian/patches/CVE-2026-19672.patch: backport of cpython
97688346ada2df3e5b9c279348862c3d64ab0823 (gh-155999), which normalizes a member
name containing a '..' component before the containment check, plus its
regression test test_parent_dir_out_and_back. Applied after CVE-2026-87910.patch.
Behaviour change: normalization removes internal '..' components, which may
change the meaning of a member name that traverses symbolic links.
Updated packages:
-
alt-python38-3.8.20-28.el8.x86_64.rpm
sha:c08e376a5e96aac4b63931bc0b289b6bdde23571492e0fe48ed44b88ee9c65e0
-
alt-python38-debug-3.8.20-28.el8.x86_64.rpm
sha:ed19a3df8c32ef3dbfe3fd2f58a4db4a991573d3fdd725709794b5db13cd14ef
-
alt-python38-devel-3.8.20-28.el8.x86_64.rpm
sha:83331f4948becb68aea5d647711eafd274e812fb8a41de49af4621d17075d399
-
alt-python38-idle-3.8.20-28.el8.x86_64.rpm
sha:894b055e0dded642b5c42314cb060d329c7627409e4e3a7bb06ecd8571ec6ee2
-
alt-python38-libs-3.8.20-28.el8.x86_64.rpm
sha:be68806801832ea905d011f17d02c0fefb776f91e88f1f4fba130c24dddb994f
-
alt-python38-test-3.8.20-28.el8.x86_64.rpm
sha:e91b50ff362ebd7eac1e126d0a5bf614b3c701308dc2a9883e110ecff9299c57
-
alt-python38-tkinter-3.8.20-28.el8.x86_64.rpm
sha:e9ddb3b0322208ed5a5d61f5ec29f07e1a085d23c56505aad14866e5fa5aab9a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.