Release date:
2026-07-30 09:25:17 UTC
Description:
- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to
_extract_one(), so on the code path that extracts a hardlink the filter was
silently dropped. An archive extracted with filter='data' could therefore
create files with an attacker-chosen uid/gid instead of the filtered values
(CWE-noinfo: incorrect enforcement of an extraction filter). Backport of
cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to
_extract_one().
Updated packages:
-
alt-python39-3.9.23-24.el7.x86_64.rpm
sha:ca3052fde20e096c23bc75cbe45a01d8137af8e293df4d8ac710b51e50f0c1be
-
alt-python39-debug-3.9.23-24.el7.x86_64.rpm
sha:5a4c42cacd48f452a0c09e22177be83cab5531ab20ed8a34b620d4d6672d25fd
-
alt-python39-devel-3.9.23-24.el7.x86_64.rpm
sha:63b24c3e0bb423397b88c1d1ff655026cb28e915adb8faac6cc2909a820dc3e3
-
alt-python39-idle-3.9.23-24.el7.x86_64.rpm
sha:40fcfb71bf56e7392cf0c40596be6745ca793854ccb35c55b60bd54a5ed651dd
-
alt-python39-libs-3.9.23-24.el7.x86_64.rpm
sha:c78ed9b7055c096143b9f2f6c0cf7aab965e7c999805ab71dc9e6b6cf54cc672
-
alt-python39-test-3.9.23-24.el7.x86_64.rpm
sha:43e2fc6afd8110b6229219f43ca249471e3060dbe1523f854f2fbf8776ad9470
-
alt-python39-tkinter-3.9.23-24.el7.x86_64.rpm
sha:068ef50a2ddcb9aefc43f9a7a3262229aae0605ec4f47569efa664409114cb88
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.