[CLSA-2026:1785405357] Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:56:11 UTC
Description:
* SECURITY UPDATE: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path where a hardlink is extracted rather than linked the filter was silently dropped. An archive extracted with filter='data' could therefore end up creating files with an attacker-chosen uid/gid instead of the values the filter would have enforced (incorrect enforcement of an extraction filter). - debian/patches/CVE-2026-4360.patch: backport of cpython 7ccdbaba (gh-151987). extract() now passes filter_function through to _extract_one(). - CVE-2026-4360
Updated packages:
  • alt-python39_3.9.23-26_amd64.deb
    sha:d45420bc9a3736f544062e20088e7d1a54b7536a
  • alt-python39-debug_3.9.23-26_amd64.deb
    sha:a0efdfa6d8bd41fb052ad728c9cab82fc06ec37b
  • alt-python39-devel_3.9.23-26_amd64.deb
    sha:eb530b0c98dd16bd7dfad9c4774c1dad764018e0
  • alt-python39-idle_3.9.23-26_amd64.deb
    sha:73d8ac5be7e6a67be80ab7f334d2f35aae27afa1
  • alt-python39-libs_3.9.23-26_amd64.deb
    sha:9551ef8f56875733eb1fb2286d8503c2ece0f4fa
  • alt-python39-test_3.9.23-26_amd64.deb
    sha:1ba1cb0a581d79a6be8ad877a587b3dabafc02eb
  • alt-python39-tkinter_3.9.23-26_amd64.deb
    sha:761b2e3899b543af2dc986aa1fee002f1de442b3
  • alt-python39_3.9.23-26_arm64.deb
    sha:e0f29ebd9fe201b308a86c989ed470d7f9ca8c35
  • alt-python39-debug_3.9.23-26_arm64.deb
    sha:2cd1f281e942b165194e20613b83e6cb380cfef3
  • alt-python39-devel_3.9.23-26_arm64.deb
    sha:a1e2d7010db9bc0e9671de2ecd3bff6952ad9d17
  • alt-python39-idle_3.9.23-26_arm64.deb
    sha:6292be5d3112f569bc3d4d548cde4392dc0c76d9
  • alt-python39-libs_3.9.23-26_arm64.deb
    sha:a9780ffe957483f49f4e59fa3d71f4aaade4d58f
  • alt-python39-test_3.9.23-26_arm64.deb
    sha:77c728816bac4565e46ac98fa23d869dd42239ef
  • alt-python39-tkinter_3.9.23-26_arm64.deb
    sha:b7d6d2fb7b5aa85ce074614606383314a5625ee1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.