[CLSA-2026:1790700140] alt-python313: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-29 16:42:31 UTC
Description:
- CVE-2026-87910: keep the result of the first filter_function() call in tarfile's makelink_with_filter() and return early when it is None, so a filter that skips a member by returning None is honoured when link extraction falls back to copying the target under the link's own, shallower name, instead of the member being extracted anyway. Carries upstream's test_extract_filters_target_none. The doubled filter call this fixes is the CVE-2026-11940 guard, which is native in 3.13.15 and is not carried by a patch of ours - CVE-2026-19672: collapse ".." components with os.path.normpath() in tarfile's _get_filtered_attrs() before the containment check, so a member whose name leaves the destination and comes back, such as "../evil/../dest/sub/file", no longer creates the intermediate directories outside the destination under the "tar" and "data" filters. The containment check looked at the resolved path, which stayed inside, while the directories were created from the name as given. Backport of upstream commit 97688346ada2. Carries upstream's test_parent_dir_out_and_back
Updated packages:
  • alt-python313-3.13.15-4.el8.x86_64.rpm
    sha:88c6037587e63a8898558e5363e62764634429fa9f724612403f7ee1f70323da
  • alt-python313-debug-3.13.15-4.el8.x86_64.rpm
    sha:f297bf40e71f17d90c4462561f97f914041c24533bb2f17a2ad152ca1bce8216
  • alt-python313-devel-3.13.15-4.el8.x86_64.rpm
    sha:d19111df49b1771fdf929d4148fdbed194b63de0698f04bc2de28bb062ab6267
  • alt-python313-idle-3.13.15-4.el8.x86_64.rpm
    sha:9474c5513aa5f04f0b0fe6f0575c117f928d65915cda24dab1bd80a4762feab9
  • alt-python313-libs-3.13.15-4.el8.x86_64.rpm
    sha:1cb395c1b5e302a05bb0156161b326cfd62f2882b8b4454014ca99272bfb8cbd
  • alt-python313-test-3.13.15-4.el8.x86_64.rpm
    sha:158ff70ddde7890c717123ad6d753d95020a21a593b6b3726bbda6c3be897d74
  • alt-python313-tkinter-3.13.15-4.el8.x86_64.rpm
    sha:0a553fb027020262e14828d1fd60f2d0e428267dc01ba445eb5363f3bef698a5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.