Release date:
2026-08-12 16:19:33 UTC
Description:
* SECURITY UPDATE: tarfile.data_filter could be bypassed using crafted
link entries, including symlinks with empty or directory-like names,
to redirect later archive members outside the intended extraction
directory, so tarfile.extractall() could write files outside the
destination directory.
- debian/patches/CVE-2026-7774.patch: backport of cpython c063191c
([3.10] branch variant of 57841198, gh-149486). data_filter now
validates the normalised link target that is actually written to
disk, resolves a symlink's target relative to its member name with
trailing separators stripped, and rejects link members that would
replace the destination directory itself.
- CVE-2026-7774
* SECURITY UPDATE: ftplib.ftpcp() still called parse227() directly and
passed the source server's self-reported PASV IPv4 address to the
target server's PORT command, so a malicious source FTP server could
redirect the target's data connection to an arbitrary host:port
(SSRF); the CVE-2021-4189 fix only covered FTP.makepasv().
- debian/patches/CVE-2026-8328.patch: backport of cpython eac4fe3b
(gh-87451). ftpcp() now uses the source server's actual peer
address unless trust_server_pasv_ipv4_address is set, the same
rule FTP.makepasv() already applies.
- CVE-2026-8328
Updated packages:
-
alt-python36_3.6.15-43_amd64.deb
sha:3b04a9c6c87aee32cc02bc3007d751e93f71a856
-
alt-python36-debug_3.6.15-43_amd64.deb
sha:9f551743e2bdbcfb3e910811fca81efce5390ef7
-
alt-python36-devel_3.6.15-43_amd64.deb
sha:5bf69650f095e2955af9152cb16ec73c175bc6e4
-
alt-python36-libs_3.6.15-43_amd64.deb
sha:5fc875d37dc5e1da1a77f58c009cb1c6886beb77
-
alt-python36-test_3.6.15-43_amd64.deb
sha:04da6f972eee1a0f15af01d985399610b3045712
-
alt-python36-tkinter_3.6.15-43_amd64.deb
sha:383207755c049c88e1183613d4a2c2fc32b6b9bc
-
alt-python36-tools_3.6.15-43_amd64.deb
sha:1431687ab1e4f31ad4186609135222c5029519e3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.