Release date:
2026-08-12 17:22:09 UTC
Description:
- CVE-2026-7774: tarfile: fix data_filter bypass via crafted link entries;
validate the normalised link target that is actually written to disk,
resolve symlink targets relative to the member name with trailing
separators stripped, and reject link members (including symlinks with
empty or directory-like names) that would replace the destination
directory itself and redirect later members outside it
- CVE-2026-8328: ftplib: apply the CVE-2021-4189 PASV anti-SSRF fix to
ftpcp(): use the source server's real peer address instead of the
attacker-controllable IPv4 address from the PASV reply unless
trust_server_pasv_ipv4_address is set
Updated packages:
-
alt-python36-3.6.15-34.el9.x86_64.rpm
sha:0780f5e12804a2e4b6c83ce550912a4b86950be9cad3f8875ffaa523dda0c5f6
-
alt-python36-debug-3.6.15-34.el9.x86_64.rpm
sha:bcc99779775b4ea0ee6b52fd00212ce3948643fccacefaaf4d84164a6130821f
-
alt-python36-devel-3.6.15-34.el9.x86_64.rpm
sha:3b998b2c418b4e24c478a95e4c1327b1e9f27d18c983a8491983b2bfdf478a13
-
alt-python36-libs-3.6.15-34.el9.x86_64.rpm
sha:67a7fdc24db522aa8260c22f9a9b3328605863903934cbcfee86861227ecb2c9
-
alt-python36-test-3.6.15-34.el9.x86_64.rpm
sha:540716fe9cc7b3b0f6e51b2f1045520c5fdefa578b3279d0d425e6d78611a6f3
-
alt-python36-tkinter-3.6.15-34.el9.x86_64.rpm
sha:c6f1e50e265b10a0733e14ae5477aa8099d02baf20919833cde1414f11caa482
-
alt-python36-tools-3.6.15-34.el9.x86_64.rpm
sha:0669c95e12935bdc9f3498c67fffafde3fc5a266caad0941aabbe2f12efc9345
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.