[CLSA-2026:1785403489] alt-python39: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:25:17 UTC
Description:
- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path that extracts a hardlink the filter was silently dropped. An archive extracted with filter='data' could therefore create files with an attacker-chosen uid/gid instead of the filtered values (CWE-noinfo: incorrect enforcement of an extraction filter). Backport of cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to _extract_one().
Updated packages:
  • alt-python39-3.9.23-24.el7.x86_64.rpm
    sha:ca3052fde20e096c23bc75cbe45a01d8137af8e293df4d8ac710b51e50f0c1be
  • alt-python39-debug-3.9.23-24.el7.x86_64.rpm
    sha:5a4c42cacd48f452a0c09e22177be83cab5531ab20ed8a34b620d4d6672d25fd
  • alt-python39-devel-3.9.23-24.el7.x86_64.rpm
    sha:63b24c3e0bb423397b88c1d1ff655026cb28e915adb8faac6cc2909a820dc3e3
  • alt-python39-idle-3.9.23-24.el7.x86_64.rpm
    sha:40fcfb71bf56e7392cf0c40596be6745ca793854ccb35c55b60bd54a5ed651dd
  • alt-python39-libs-3.9.23-24.el7.x86_64.rpm
    sha:c78ed9b7055c096143b9f2f6c0cf7aab965e7c999805ab71dc9e6b6cf54cc672
  • alt-python39-test-3.9.23-24.el7.x86_64.rpm
    sha:43e2fc6afd8110b6229219f43ca249471e3060dbe1523f854f2fbf8776ad9470
  • alt-python39-tkinter-3.9.23-24.el7.x86_64.rpm
    sha:068ef50a2ddcb9aefc43f9a7a3262229aae0605ec4f47569efa664409114cb88
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.