[CLSA-2026:1785173685] Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2026-07-27 17:34:58 UTC
Description:
* SECURITY UPDATE: Mercurial configuration injection via VCS URL revision - debian/patches/CVE-2023-5752.patch: pass revision as --rev= so it cannot be misinterpreted as an option by hg - CVE-2023-5752 * SECURITY UPDATE: symlink targets not validated in tar extraction - debian/patches/CVE-2025-8869.patch: require symlink members of sdist tar archives to point at files inside the archive - CVE-2025-8869 * SECURITY UPDATE: path traversal via prefix matching when extracting - debian/patches/CVE-2026-1703.patch: use an explicit path-component containment check instead of commonprefix in is_within_directory - CVE-2026-1703 * SECURITY UPDATE: concatenated tar/ZIP archives misinterpreted as ZIP - debian/patches/CVE-2026-3219.patch: pick archive format by content type, extension, then unambiguous magic signature - CVE-2026-3219 * SECURITY UPDATE: self-version check ran after installing wheels - debian/patches/CVE-2026-6357.patch: compute the self-update check before the install command body runs - CVE-2026-6357
Updated packages:
  • alt-python38-pip_22.2.1-5_all.deb
    sha:5ddb237ef5a0132f47de6636241268be15cdb426
  • alt-python38-pip-wheel_22.2.1-5_all.deb
    sha:96ecbc8dc356db9f76a7c94147a2477f315cf6c7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.