[CLSA-2026:1786548590] alt-python38: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 15:30:02 UTC
Description:
- CVE-2026-11940: tarfile: fix extraction-filter bypass via the hardlink-to-symlink extraction fallback; makelink_with_filter now re-runs the filter on the member re-rooted at the link's own path, so a crafted archive can no longer recreate a validated deeper symlink at a shallower path escaping the destination (incomplete fix of CVE-2025-4330) - CVE-2026-0864: configparser: normalize all line endings (CR, CRLF, LF) to '\n\t' when writing, preventing injection of unexpected keys, values, or sections through carriage returns in written values - CVE-2026-11972: tarfile: break _Stream.seek() at EOF in streaming mode (mode="r|"), preventing a CPU denial-of-service when a forged member header declares a huge size against an already-exhausted stream - CVE-2026-4360: tarfile: forward filter_function from TarFile.extract() to _extract_one(), so the hardlink/symlink extraction fallback applies the extraction filter on the single-member extract() path too; previously attacker-controlled mode, uid and gid were applied verbatim even with filter='data' and the CVE-2025-4330/CVE-2026-11940 fallback checks never ran there (cpython 7ccdbaba, gh-151987, follow-up to gh-151558)
Updated packages:
  • alt-python38-3.8.20-22.el7.x86_64.rpm
    sha:ff43c20b06bce923ad234f9360952781ea1a82bf0e6955a5af9d33f2da6de557
  • alt-python38-debug-3.8.20-22.el7.x86_64.rpm
    sha:672bcba3e32bfca0a76e5b7e4d0d4dfedc1edf70f6cd27c5e232ed2dc998b179
  • alt-python38-devel-3.8.20-22.el7.x86_64.rpm
    sha:c4b385cf3b72a0765652d9e271edd9abdcdfd4844b40041e3c41675f1ec5e08d
  • alt-python38-idle-3.8.20-22.el7.x86_64.rpm
    sha:29899b7820f1b9179f7fb76fc8087b4adbeade1781f82a25b25240106c3bbb63
  • alt-python38-libs-3.8.20-22.el7.x86_64.rpm
    sha:19ba88db3852742238d5abb74fd8e2f0713bed1ce6d722ba406eb0f317448a3d
  • alt-python38-test-3.8.20-22.el7.x86_64.rpm
    sha:c11a7d05f4caaaf1992e74c444f384c63c88792411cb0efd9865e741f5a4c1fb
  • alt-python38-tkinter-3.8.20-22.el7.x86_64.rpm
    sha:54bbb4c9ffbc5cf3e0fe5fe3a27cac772fb7da6b1444cc425d95e5eca255de64
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.