Release date:
2026-08-12 17:27:19 UTC
Description:
- CVE-2026-7774: tarfile: fix data_filter bypass via crafted link entries;
validate the normalised link target that is actually written to disk,
resolve symlink targets relative to the member name with trailing
separators stripped, and reject link members (including symlinks with
empty or directory-like names) that would replace the destination
directory itself and redirect later members outside it
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
ftpcp(): use the source server's real peer address instead of the
attacker-controllable IPv4 address from the PASV reply unless
trust_server_pasv_ipv4_address is set
Updated packages:
-
alt-python36-3.6.15-34.el8.x86_64.rpm
sha:ee3607e3b79bf11bdc3d810bfb67e92118e091b6b5a988d2c46fb78fbc596c0b
-
alt-python36-debug-3.6.15-34.el8.x86_64.rpm
sha:59c8fa6f6f71327217a82816536eb1fafb68cd8fe6b1bcd04e3ad54f9d7fe0f2
-
alt-python36-devel-3.6.15-34.el8.x86_64.rpm
sha:04e932e34df4a85b78dc314ee8edef000b06eb821feee3b7ac0f1e4730f371db
-
alt-python36-libs-3.6.15-34.el8.x86_64.rpm
sha:bbc874c99079b325f449acc022e9225910d939813d38950ed30fca70c70a4a92
-
alt-python36-test-3.6.15-34.el8.x86_64.rpm
sha:f2b5185d1b93f16f7df5f7f698b0539c99612695661bd6af7b74dab15dc87d9d
-
alt-python36-tkinter-3.6.15-34.el8.x86_64.rpm
sha:5b480115cea201b8bafd9e6895c81cc42125724bf24aff4f2b481cbea66bd66a
-
alt-python36-tools-3.6.15-34.el8.x86_64.rpm
sha:31bd18176bda6dcf8e4c0b17355747255d100f51a2472421752550a49c6a2d04
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.