[CLSA-2026:1785168595] Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 16:10:11 UTC
Description:
* SECURITY UPDATE: Mercurial option injection via crafted VCS revision - debian/patches/CVE-2023-5752.patch: pass the revision to hg as --rev= - CVE-2023-5752 * SECURITY UPDATE: arbitrary file overwrite via symlinks in sdist tarballs - debian/patches/CVE-2025-8869.patch: check symlink targets stay inside the extraction directory in untar_file - CVE-2025-8869 * SECURITY UPDATE: archive confusion via tar/ZIP polyglot files - debian/patches/CVE-2026-3219.patch: order unpack_file checks by confidence and reject ambiguous archive signatures - CVE-2026-3219 * SECURITY UPDATE: path traversal via string-prefix sibling directories - debian/patches/CVE-2026-1703.patch: use os.path.commonpath instead of commonprefix in is_within_directory - CVE-2026-1703 * SECURITY UPDATE: code execution via post-install pip self-version check - debian/patches/CVE-2026-6357.patch: fetch version info before command execution, only emit the upgrade warning afterwards - CVE-2026-6357
Updated packages:
  • alt-python311-pip_21.3.1-4_all.deb
    sha:71a1c1155b9c2d9610f6a7f7ece5b9ca57a00838
  • alt-python311-pip-wheel_21.3.1-4_all.deb
    sha:5695addf08c420f7f96b3b4434d463cd12297893
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.