[CLSA-2026:1785402802] alt-python39: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:13:37 UTC
Description:
- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path that extracts a hardlink the filter was silently dropped. An archive extracted with filter='data' could therefore create files with an attacker-chosen uid/gid instead of the filtered values (CWE-noinfo: incorrect enforcement of an extraction filter). Backport of cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to _extract_one().
Updated packages:
  • alt-python39-3.9.23-24.el10.x86_64.rpm
    sha:22ef42f051c6ecf46e785113279101c5e7b64cdbd146d68aee2a88215ea325b7
  • alt-python39-debug-3.9.23-24.el10.x86_64.rpm
    sha:c476f88de78621e895b116203d0207496c28f1db9fae69c431bebcb0e276cc6e
  • alt-python39-devel-3.9.23-24.el10.x86_64.rpm
    sha:9ae46ea4cd8f0b66b3da9f404aeb2e7d738f0e2c31da169583aaf80556ca2096
  • alt-python39-idle-3.9.23-24.el10.x86_64.rpm
    sha:b67240f0884c84d0e1cf909003c18b50e75a895e2599e9e59dcf139764023253
  • alt-python39-libs-3.9.23-24.el10.x86_64.rpm
    sha:1a3097036e40e647b900041d034b93f1f6833dcc857f0f0a08c030cb1f93cc50
  • alt-python39-test-3.9.23-24.el10.x86_64.rpm
    sha:d6502112d7d6c11616aced02809ca69191ee77acea519a968da440ca430f90af
  • alt-python39-tkinter-3.9.23-24.el10.x86_64.rpm
    sha:e6995f12935d8595b841e944ecedd2c7d7d5e8290a1bc2c0723a710e3b30c925
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.