Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-7774

Опубликовано: 04 июн. 2026
Источник: debian

Описание

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.6-1package
python3.13fixed3.13.14-1package
python3.13fixed3.13.5-2+deb13u3trixiepackage
python3.11not-affectedpackage
python3.9not-affectedpackage
python2.7not-affectedpackage
pypy3unfixedpackage
pypy3no-dsatrixiepackage
pypy3not-affectedbookwormpackage
pypy3not-affectedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/06/04/9

  • https://github.com/python/cpython/pull/149487

  • https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da (main)

  • https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558 (v3.15.0b2)

  • https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf (3.14 branch)

  • https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2 (3.13 branch)

  • https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d (3.12 branch)

  • Same code situation as with CVE-2025-4435.

Связанные уязвимости

ubuntu
4 месяца назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

CVSS3: 6.5
redhat
4 месяца назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

nvd
4 месяца назад

tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.

msrc
3 месяца назад

tarfile.data_filter path traversal bypass allows writing outside the extraction directory

suse-cvrf
20 дней назад

Security update for python310