[CLSA-2026:1785404249] Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:37:50 UTC
Description:
* SECURITY UPDATE: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path where a hardlink is extracted rather than linked the filter was silently dropped. An archive extracted with filter='data' could therefore end up creating files with an attacker-chosen uid/gid instead of the values the filter would have enforced (incorrect enforcement of an extraction filter). - debian/patches/CVE-2026-4360.patch: backport of cpython 7ccdbaba (gh-151987). extract() now passes filter_function through to _extract_one(). - CVE-2026-4360
Updated packages:
  • alt-python39_3.9.23-26_amd64.deb
    sha:f50a1af1da44eda1f16583f98a5c0d373dc0d91c
  • alt-python39-debug_3.9.23-26_amd64.deb
    sha:50af4488fb05840251a4548bbf79086cf2882123
  • alt-python39-devel_3.9.23-26_amd64.deb
    sha:81c82956b0f56a71cc305b46f09d226b11e4eb82
  • alt-python39-idle_3.9.23-26_amd64.deb
    sha:f2e1f094089c86460903baea40ce028076de3fe1
  • alt-python39-libs_3.9.23-26_amd64.deb
    sha:14baa30c52c0356f4c44ecedda563e8e36cfe873
  • alt-python39-test_3.9.23-26_amd64.deb
    sha:50f8ed9b148a0fd811b1f2e3dfc0a2e13524f7ac
  • alt-python39-tkinter_3.9.23-26_amd64.deb
    sha:2a4bdcf84093c514bd9b4b5e854abf9a4475d649
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.