[CLSA-2026:1786679975] alt-python38: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-14 03:59:46 UTC
Description:
- CVE-2026-7774: tarfile: make data_filter validate the normalised link target that is actually written to disk, strip trailing separators from a symlink member's name before resolving its directory, and reject link members that resolve to the destination directory itself, closing path-traversal bypasses of the 'data' extraction filter via crafted link entries (symlinks with empty or directory-like names) - Register TestFtpcpSecurity (CVE-2026-8328) in test_ftplib's test_main so regrtest actually runs the test (fixes an omission in the original backport; no functional change to the CVE fix itself)
Updated packages:
  • alt-python38-3.8.20-24.el9.x86_64.rpm
    sha:077e3ee1f52832eec83af54938c4dd556010292d6b91ab7728e5f8a0f2b5d226
  • alt-python38-devel-3.8.20-24.el9.x86_64.rpm
    sha:0333251c826d605aab5bb29ddacea3e46b5bb7dd70653145facbf177b27caa96
  • alt-python38-idle-3.8.20-24.el9.x86_64.rpm
    sha:42f4639dbc977d12489e60cd35446095e06ee6c474170c59feb12cc08ce0a512
  • alt-python38-libs-3.8.20-24.el9.x86_64.rpm
    sha:504bd01dbb00b1c6c89c049195b91f251cd683212925be59663489e040137857
  • alt-python38-test-3.8.20-24.el9.x86_64.rpm
    sha:ca360d89c23e45a924e1547dba732deaeabeaea7ab6db83f2e89746a445c9d4a
  • alt-python38-tkinter-3.8.20-24.el9.x86_64.rpm
    sha:86aa9d6ab761faec2d76845857c6b37503fb55673beeee0e91d1ca3b806f48c4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.