[CLSA-2026:1785403906] alt-python39: Fix of 7 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 09:32:08 UTC
Description:
- CVE-2026-4360: TarFile.extract() did not forward the caller's filter to _extract_one(), so on the code path that extracts a hardlink the filter was silently dropped. An archive extracted with filter='data' could therefore create files with an attacker-chosen uid/gid instead of the filtered values (CWE-noinfo: incorrect enforcement of an extraction filter). Backport of cpython 7ccdbaba (gh-151987): extract() now passes filter_function through to _extract_one().
Updated packages:
  • alt-python39-3.9.23-24.el9.x86_64.rpm
    sha:f66a58e40e6473350cc15a32ed4bd8facdd50a6395d54e25b195841c6da4e565
  • alt-python39-debug-3.9.23-24.el9.x86_64.rpm
    sha:3f63fe6458722f72f2e6e59c93ac41f959ff27f1b8653f66027d9d7ea447c9b5
  • alt-python39-devel-3.9.23-24.el9.x86_64.rpm
    sha:60e2e5a4438f0d134af2a1057b6855177ed938d7eae4723aa2cf5c9a9f133b66
  • alt-python39-idle-3.9.23-24.el9.x86_64.rpm
    sha:818b89ef922d52f5b73d0ff2c4c6844c560771add61b6b97bf59badedb556937
  • alt-python39-libs-3.9.23-24.el9.x86_64.rpm
    sha:0460ed32efb00399130e48d278eb6032afab69710f1762f8aafacdbe8a3bbe2c
  • alt-python39-test-3.9.23-24.el9.x86_64.rpm
    sha:e65c7fd9736102bc37dbef26d9d9c5627a40996a7eece39ad2abff7a6eb4c3d6
  • alt-python39-tkinter-3.9.23-24.el9.x86_64.rpm
    sha:f9d8e9197c146a94cf7dbdfbc681d7686db4e447ae3e83a4d90aee016dbe94e8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.