[CLSA-2026:1785403125] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:19:03 UTC
Description:
* SECURITY UPDATE: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path where a hardlink is extracted rather than linked the filter was silently dropped. An archive extracted with filter='data' could therefore end up creating files with an attacker-chosen uid/gid instead of the values the filter would have enforced (incorrect enforcement of an extraction filter). - debian/patches/CVE-2026-4360.patch: backport of cpython 7ccdbaba (gh-151987). extract() now passes filter_function through to _extract_one(). - CVE-2026-4360
Updated packages:
  • alt-python39_3.9.23-26_amd64.deb
    sha:2c3dc5b6acdc432fec3c0cf5a7a94a8629906ddb
  • alt-python39-debug_3.9.23-26_amd64.deb
    sha:1e804ef117956b3bd7f9e9b97ea6252239bfcc85
  • alt-python39-devel_3.9.23-26_amd64.deb
    sha:79e0ec4ac0b8d454b3a5c6b6af184a5fa7939083
  • alt-python39-idle_3.9.23-26_amd64.deb
    sha:406f4d3d4b64d2363fbbc67cfca4484b06a0ebf7
  • alt-python39-libs_3.9.23-26_amd64.deb
    sha:e0bd63e5b20aa975381165e23ec8919f09554538
  • alt-python39-test_3.9.23-26_amd64.deb
    sha:aac324dde7ae9a937e5e3addd5c48d25f11d8d9c
  • alt-python39-tkinter_3.9.23-26_amd64.deb
    sha:c6df5169c5dac998297704609612fa0d5e2696fc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.