[CLSA-2026:1785489032] Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-31 09:10:50 UTC
Description:
* SECURITY UPDATE: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path where a hardlink is extracted rather than linked the filter was silently dropped. An archive extracted with filter='data' could therefore end up creating files with an attacker-chosen uid/gid instead of the values the filter would have enforced (incorrect enforcement of an extraction filter). - debian/patches/CVE-2026-4360.patch: backport of cpython 7ccdbaba (gh-151987). extract() now passes filter_function through to _extract_one(). - CVE-2026-4360
Updated packages:
  • alt-python39_3.9.23-26_amd64.deb
    sha:dff8d8e3c380e59ad37706f21fd7e933413ff2bd
  • alt-python39-debug_3.9.23-26_amd64.deb
    sha:f94fc05d3188fe4950eaab30836de3be3c130d5f
  • alt-python39-devel_3.9.23-26_amd64.deb
    sha:90ae73214767ac7033f9e7f0461a372801907dca
  • alt-python39-idle_3.9.23-26_amd64.deb
    sha:13d7d3dc43b34553c1c97be463f872913a6cee8b
  • alt-python39-libs_3.9.23-26_amd64.deb
    sha:0dcc10103f9ecf2f136f3ae4e76ee4b039b17186
  • alt-python39-test_3.9.23-26_amd64.deb
    sha:b068c53b40e8035609ba5fa90159c13e151efe06
  • alt-python39-tkinter_3.9.23-26_amd64.deb
    sha:6bfc932bc8c091e2bed93eeb86f7ee0f092ec33f
  • alt-python39_3.9.23-26_arm64.deb
    sha:d33ab61c8f79e1fd2f0279e74ab0bdd65c370129
  • alt-python39-debug_3.9.23-26_arm64.deb
    sha:c66653b2f8896face8bb140256ecc5ba319a5c8d
  • alt-python39-devel_3.9.23-26_arm64.deb
    sha:0c44bb398dd294f8938374ff615d7fba1d06f4e7
  • alt-python39-idle_3.9.23-26_arm64.deb
    sha:557a9a9e9332b42a8d20cff453f15e5a6ea84adb
  • alt-python39-libs_3.9.23-26_arm64.deb
    sha:663e154a3886c5a15a5a723d2aa6e7c21a2c6977
  • alt-python39-test_3.9.23-26_arm64.deb
    sha:d8a72627c8a6729f15a75b0ee02b0b358f478ea3
  • alt-python39-tkinter_3.9.23-26_arm64.deb
    sha:6a6c9c549b627baac245e704b8e05c86b5454ea3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.