[CLSA-2026:1785844339] python: Fix of CVE-2026-11972
Type:
security
Severity:
Important
Release date:
2026-08-04 11:52:30 UTC
Description:
- CVE-2026-11972: stop tarfile._Stream.seek() from spinning past end of stream - the loop read whole blocks according to the member size declared in the header and ignored what read() returned, so a header announcing a huge size (e.g. 2**64) kept it going against an already exhausted stream and hung any application walking an untrusted archive opened in streaming mode (mode='r|'). Backported from upstream CPython (gh-151981, GH-151982).
CVEs fixed:
Updated packages:
  • python-2.7.5-94.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:7d982f072c628c9ac623fd9e300e21cbd8a9e64bd6819a0461a97d1405495b0c
  • python-debug-2.7.5-94.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:8e672389e670e31979a30a544e00d1abb106af4fc5ea148ea8a1d4a090d7a037
  • python-devel-2.7.5-94.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:52192389f53bcedf9e49209e1347a785157a9dd9b82952169abc67c6d3695822
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els13.i686.rpm
    sha:7cf9304225dec34fe5cf7eb8b716eccceb213e7010a58108aff1e7332973ea96
  • python-libs-2.7.5-94.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:00ead1b8e79dcaaacdd6337576afa0d8633ed6082f6dbf1706c3505858f3412f
  • python-test-2.7.5-94.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:7498d9745c274251d20d58c5f39bb809a151a97222664d95f6174cda711f8dfd
  • python-tools-2.7.5-94.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:ea63878728af50f5a5aa2c66fd203d0fec10cdacda102df1ced65e99763069b3
  • tkinter-2.7.5-94.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:1b232f529939c9109c78dc855951b723aace9d32f9cdb3aa212ca2e4554b4a08
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.