[CLSA-2026:1787230438] Fix of 5 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-20 12:54:12 UTC
Description:
* SECURITY UPDATE: option injection via Mercurial revision passed as a bare argument - debian/patches/CVE-2023-5752.patch: pass the revision as --rev= so it cannot be interpreted as an hg option - CVE-2023-5752 * SECURITY UPDATE: arbitrary file write via unchecked symlink targets in tar extraction - debian/patches/CVE-2025-8869.patch: reject symlink members whose target is absent from the archive or resolves outside the destination directory - CVE-2025-8869 * SECURITY UPDATE: path traversal via sibling-prefix directory containment check - debian/patches/CVE-2026-1703.patch: compare whole path components instead of using os.path.commonprefix - CVE-2026-1703 * SECURITY UPDATE: archive format confusion for files matching both zip and tar signatures - debian/patches/CVE-2026-3219.patch: order format detection by confidence and refuse archives with an ambiguous signature - CVE-2026-3219 * SECURITY UPDATE: arbitrary file write via entry point name escaping the scripts directory - debian/patches/CVE-2026-8643.patch: reject console script names that do not resolve inside the scripts directory - CVE-2026-8643
Updated packages:
  • alt-python36-pip_20.2.4-8_all.deb
    sha:708e43019b26e23147d90967b2ef4ed09b7175c3
  • alt-python36-pip-wheel_20.2.4-8_all.deb
    sha:a59ea8b66033537e7c08594290ab11765e128807
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.