Release date:
2026-07-30 09:49:26 UTC
Description:
- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to
_extract_one(), so on the code path that extracts a hardlink the filter was
silently dropped. An archive extracted with filter='data' could therefore
create files with an attacker-chosen uid/gid instead of the filtered values
(CWE-noinfo: incorrect enforcement of an extraction filter). Backport of
cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to
_extract_one().
Updated packages:
-
alt-python39-3.9.23-24.el8.x86_64.rpm
sha:8be53e6b4e1eb06b9c3bf346b6ada4e9a30c812a864540d80c139c42ae5df062
-
alt-python39-debug-3.9.23-24.el8.x86_64.rpm
sha:db905c6881fa17f7bd7462a0f7e36b32204c31add32dadeaecf28f27155fa723
-
alt-python39-devel-3.9.23-24.el8.x86_64.rpm
sha:6fd69f984bcb6ea3d55b248851444fefe4de17b3a15967a24ec3dd5b42fd30a1
-
alt-python39-idle-3.9.23-24.el8.x86_64.rpm
sha:068a16a7fe2a21a6da328fb16f5b20927cda84757fae48c41beb9f46e14d3e6d
-
alt-python39-libs-3.9.23-24.el8.x86_64.rpm
sha:22a5af4ba80fa89c929a3df1d0605a2e6d3fdaf43345db07d0b8effd1ce56659
-
alt-python39-test-3.9.23-24.el8.x86_64.rpm
sha:cf87431678ccf22013fd88545baa57aa55b33861f36aab8255f729a129b30ce7
-
alt-python39-tkinter-3.9.23-24.el8.x86_64.rpm
sha:6a1c9d1d0f75451764d25478b82efa0e3b48ab371733a5666f7111c0848e36a7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.