Release date:
2026-07-30 09:13:37 UTC
Description:
- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to
_extract_one(), so on the code path that extracts a hardlink the filter was
silently dropped. An archive extracted with filter='data' could therefore
create files with an attacker-chosen uid/gid instead of the filtered values
(CWE-noinfo: incorrect enforcement of an extraction filter). Backport of
cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to
_extract_one().
Updated packages:
-
alt-python39-3.9.23-24.el10.x86_64.rpm
sha:22ef42f051c6ecf46e785113279101c5e7b64cdbd146d68aee2a88215ea325b7
-
alt-python39-debug-3.9.23-24.el10.x86_64.rpm
sha:c476f88de78621e895b116203d0207496c28f1db9fae69c431bebcb0e276cc6e
-
alt-python39-devel-3.9.23-24.el10.x86_64.rpm
sha:9ae46ea4cd8f0b66b3da9f404aeb2e7d738f0e2c31da169583aaf80556ca2096
-
alt-python39-idle-3.9.23-24.el10.x86_64.rpm
sha:b67240f0884c84d0e1cf909003c18b50e75a895e2599e9e59dcf139764023253
-
alt-python39-libs-3.9.23-24.el10.x86_64.rpm
sha:1a3097036e40e647b900041d034b93f1f6833dcc857f0f0a08c030cb1f93cc50
-
alt-python39-test-3.9.23-24.el10.x86_64.rpm
sha:d6502112d7d6c11616aced02809ca69191ee77acea519a968da440ca430f90af
-
alt-python39-tkinter-3.9.23-24.el10.x86_64.rpm
sha:e6995f12935d8595b841e944ecedd2c7d7d5e8290a1bc2c0723a710e3b30c925
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.