Release date:
2026-07-31 09:21:11 UTC
Description:
* SECURITY UPDATE: TarFile.extract() did not forward the caller's filter to
_extract_one(), so on the code path where a hardlink is extracted rather
than linked the filter was silently dropped. An archive extracted with
filter='data' could therefore end up creating files with an
attacker-chosen uid/gid instead of the values the filter would have
enforced (incorrect enforcement of an extraction filter).
- debian/patches/CVE-2026-4360.patch: backport of cpython 7ccdbaba
(gh-151987). extract() now passes filter_function through to
_extract_one().
- CVE-2026-4360
Updated packages:
-
alt-python39_3.9.23-26_amd64.deb
sha:a39a99b402d7c401eaf551d77263c956de256e37
-
alt-python39-debug_3.9.23-26_amd64.deb
sha:f94fc05d3188fe4950eaab30836de3be3c130d5f
-
alt-python39-devel_3.9.23-26_amd64.deb
sha:3d8b28603deb819342f9539a3f816adc5205eb6c
-
alt-python39-idle_3.9.23-26_amd64.deb
sha:263cbb339b69b261bde97da18c52a6bc7687cdd3
-
alt-python39-libs_3.9.23-26_amd64.deb
sha:6e8a315348c3fa3428df09719933a0215ac1a867
-
alt-python39-test_3.9.23-26_amd64.deb
sha:b1735c360dea7551ba416198e5c0457c29afbc11
-
alt-python39-tkinter_3.9.23-26_amd64.deb
sha:8242446533df5f7c96c1dbd7852d798164c53788
-
alt-python39_3.9.23-26_arm64.deb
sha:1bd6cd76a4cdf0d399935fa3552b0c0353bc6337
-
alt-python39-debug_3.9.23-26_arm64.deb
sha:c66653b2f8896face8bb140256ecc5ba319a5c8d
-
alt-python39-devel_3.9.23-26_arm64.deb
sha:cacf481981c4d847c322148e212fc06cc5866b5d
-
alt-python39-idle_3.9.23-26_arm64.deb
sha:47b05af2a1994d1a9283df52d20ba51ae5e87bd2
-
alt-python39-libs_3.9.23-26_arm64.deb
sha:8baf1750065d014e406fe3c3ec80b39cfbee37ca
-
alt-python39-test_3.9.23-26_arm64.deb
sha:d45d691fb93805415373b80cc61afeaf03e9bd06
-
alt-python39-tkinter_3.9.23-26_arm64.deb
sha:05660d24fdcf4f846d20df8b1fd7769ca3443eb5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.