[CLSA-2026:1790680079] alt-python310: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-29 11:08:11 UTC
Description:
- CVE-2026-87910: honour a None result from the extraction filter on tarfile's hard-link fallback path. makelink_with_filter() discarded the result of the CVE-2026-11940 re-validation call and acted only on its exceptions, so a PEP 706 custom filter that skips a member by returning None was ignored and the member was extracted anyway, under the link's name. Carries upstream's test_extract_filters_target_none. The guard being repaired is native to upstream 3.10.21, not a patch of ours - CVE-2026-19672: normalise a tarfile member name containing ".." before the containment check in _get_filtered_attrs(). The "tar" and "data" filters validated the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories were created from the name as given and landed outside it. POSIX only. Carries upstream's test_parent_dir_out_and_back as merged. Backported from upstream commit 97688346 (gh-155999). Upstream has this on 3.12+ only; the 3.10 backport pull request is still open
Updated packages:
  • alt-python310-3.10.21-3.el8.x86_64.rpm
    sha:f11202b7633ac46a18ed852830bdbfa1b5cf56c01c2101fb37fdcabdef6653af
  • alt-python310-debug-3.10.21-3.el8.x86_64.rpm
    sha:742b761224608707d53d6ac99b2307dbb6bcb125a6a3b4fc7b16cacbb731d604
  • alt-python310-devel-3.10.21-3.el8.x86_64.rpm
    sha:7ced4ffb04f35631088566e11c23914b5b2d20cd88a84eecf5d2dcc80d38fe99
  • alt-python310-idle-3.10.21-3.el8.x86_64.rpm
    sha:80861a1da81b4ea6026ee714aa0e6ebf4483c3cd328a11fa10808252e4158158
  • alt-python310-libs-3.10.21-3.el8.x86_64.rpm
    sha:b64aef833df314cc3166504ed22ec6677f7a44ddec952df013dcf075243c2d11
  • alt-python310-test-3.10.21-3.el8.x86_64.rpm
    sha:92346ce9ebf9c6e3f1dee08878d7b8140761c53462ce05bccfd487433469f03f
  • alt-python310-tkinter-3.10.21-3.el8.x86_64.rpm
    sha:a6ea55aff61f488845f9cd552da6cb4d9f108342be4395aa400944089b0a17f1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.