[CLSA-2026:1790680294] alt-python311: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-29 11:11:46 UTC
Description:
- CVE-2026-87910: honour a None result from the extraction filter on tarfile's hard-link fallback path. makelink_with_filter() discarded the result of the CVE-2026-11940 re-validation call and acted only on its exceptions, so a PEP 706 custom filter that skips a member by returning None was ignored and the member was extracted anyway, under the link's name. Carries upstream's test_extract_filters_target_none. The guard being repaired is native to upstream 3.11.16, not a patch of ours - CVE-2026-19672: normalise a tarfile member name containing ".." before the containment check in _get_filtered_attrs(). The "tar" and "data" filters validated the resolved path, which stays inside the destination for a name such as "../evil/../dest/sub/file", while the intermediate directories were created from the name as given and landed outside it. POSIX only. Carries upstream's test_parent_dir_out_and_back. Backported from upstream commit 97688346ada2 (gh-155999). Upstream has this on 3.12+ only; the 3.11 backport pull request is still open
Updated packages:
  • alt-python311-3.11.16-3.el9.x86_64.rpm
    sha:9abc2174433f3a3df15021e3ec2f39efe1cea9fa6141dfa9abf39fab11981cce
  • alt-python311-debug-3.11.16-3.el9.x86_64.rpm
    sha:a4d1a799d0d32d2d3b57276fbd3d5b429239900f19440a49d300dbca18abff99
  • alt-python311-devel-3.11.16-3.el9.x86_64.rpm
    sha:b7da10db614268d8a0a68e13b4511389b406beac452920493dd3a8b92519119a
  • alt-python311-idle-3.11.16-3.el9.x86_64.rpm
    sha:9ac38252754be1575a7de80c85587d6b065d1615377814a7a5cf463b3c26bd16
  • alt-python311-libs-3.11.16-3.el9.x86_64.rpm
    sha:089db626b576b6d6949df60b66101660b2d7997502bbd0c720de55a4ecf5160b
  • alt-python311-test-3.11.16-3.el9.x86_64.rpm
    sha:2ec3c0441644551934ed2ce492ee041a6d9406d91d45d74f49265361e278d353
  • alt-python311-tkinter-3.11.16-3.el9.x86_64.rpm
    sha:ce65592dacf4f227f263e2a8a1b0f14cdd968740681355da4c96916d3b14dc4c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.