[CLSA-2026:1787214182] Fix CVE(s): CVE-2026-4360, CVE-2026-6879
Type:
security
Severity:
Moderate
Release date:
2026-08-20 08:23:15 UTC
Description:
* SECURITY UPDATE: extraction filter bypassed for hardlink targets in tarfile.TarFile.extract() - debian/patches/CVE-2026-4360.patch: forward the resolved filter_function from extract() to _extract_one(), so that the recursive call which materialises a hardlink's target as a fallback is filtered too instead of falling back to unfiltered extraction, which let a crafted archive write the target with attributes the selected filter would have rejected (CWE-281). - CVE-2026-4360 * SECURITY UPDATE: CPU denial-of-service in xml.etree XPath index predicates - debian/patches/CVE-2026-6879.patch: memoise the indexed match per (parent, tag) pair in the ElementPath index-predicate selector instead of calling parent.findall(elem.tag) once per sibling, so patterns such as ".//a[1]" or ".//a[last()]" no longer rescan the whole sibling list for every sibling and are linear rather than quadratic in the number of same-tag siblings (CWE-407/CWE-1333). - CVE-2026-6879
Updated packages:
  • alt-python311_3.11.15-7_amd64.deb
    sha:04baa75e020493183796829a5377b96e75c9b712
  • alt-python311-debug_3.11.15-7_amd64.deb
    sha:a809d7e8672d23ee9520edd44dacc05cdc8b34d9
  • alt-python311-devel_3.11.15-7_amd64.deb
    sha:3d7e2f29cb4983d75fea5c00b684ef07a7d493f8
  • alt-python311-idle_3.11.15-7_amd64.deb
    sha:edf1f00e7d4c52e60bdeb8ed8b930793312c64a8
  • alt-python311-libs_3.11.15-7_amd64.deb
    sha:ca30f8a2de3c726488f6f0886b2e0aba4b78309c
  • alt-python311-test_3.11.15-7_amd64.deb
    sha:46af26a97061ff3cfbf06e2e8ed841f9ff1a2537
  • alt-python311-tkinter_3.11.15-7_amd64.deb
    sha:5c57d31e74ca258cd647cc6c2b9abec803d59afb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.