[CLSA-2026:1785404595] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:43:35 UTC
Description:
* SECURITY UPDATE: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path where a hardlink is extracted rather than linked the filter was silently dropped. An archive extracted with filter='data' could therefore end up creating files with an attacker-chosen uid/gid instead of the values the filter would have enforced (incorrect enforcement of an extraction filter). - debian/patches/CVE-2026-4360.patch: backport of cpython 7ccdbaba (gh-151987). extract() now passes filter_function through to _extract_one(). - CVE-2026-4360
Updated packages:
  • alt-python39_3.9.23-26_amd64.deb
    sha:c76e044bee7ec6b768a96e3521c0aa0ce48e1f8c
  • alt-python39-debug_3.9.23-26_amd64.deb
    sha:f7a9ed300d4f36996d992ead548e03896662ec60
  • alt-python39-devel_3.9.23-26_amd64.deb
    sha:049a3975a395b3c1e6aff20c2640133729f0ef01
  • alt-python39-idle_3.9.23-26_amd64.deb
    sha:036aa8fd94bef4d6876fcfd00c472a76825695ab
  • alt-python39-libs_3.9.23-26_amd64.deb
    sha:264ddf9c9696ef890d950664602f22e49dd313af
  • alt-python39-test_3.9.23-26_amd64.deb
    sha:65d58bb20ce22730f2c1978d39d33fd511dffaba
  • alt-python39-tkinter_3.9.23-26_amd64.deb
    sha:6d18f661dd581e9820ddaeea0f7b604721620a50
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.