[CLSA-2026:1785404950] alt-python39: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:49:26 UTC
Description:
- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path that extracts a hardlink the filter was silently dropped. An archive extracted with filter='data' could therefore create files with an attacker-chosen uid/gid instead of the filtered values (CWE-noinfo: incorrect enforcement of an extraction filter). Backport of cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to _extract_one().
Updated packages:
  • alt-python39-3.9.23-24.el8.x86_64.rpm
    sha:8be53e6b4e1eb06b9c3bf346b6ada4e9a30c812a864540d80c139c42ae5df062
  • alt-python39-debug-3.9.23-24.el8.x86_64.rpm
    sha:db905c6881fa17f7bd7462a0f7e36b32204c31add32dadeaecf28f27155fa723
  • alt-python39-devel-3.9.23-24.el8.x86_64.rpm
    sha:6fd69f984bcb6ea3d55b248851444fefe4de17b3a15967a24ec3dd5b42fd30a1
  • alt-python39-idle-3.9.23-24.el8.x86_64.rpm
    sha:068a16a7fe2a21a6da328fb16f5b20927cda84757fae48c41beb9f46e14d3e6d
  • alt-python39-libs-3.9.23-24.el8.x86_64.rpm
    sha:22a5af4ba80fa89c929a3df1d0605a2e6d3fdaf43345db07d0b8effd1ce56659
  • alt-python39-test-3.9.23-24.el8.x86_64.rpm
    sha:cf87431678ccf22013fd88545baa57aa55b33861f36aab8255f729a129b30ce7
  • alt-python39-tkinter-3.9.23-24.el8.x86_64.rpm
    sha:6a1c9d1d0f75451764d25478b82efa0e3b48ab371733a5666f7111c0848e36a7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.