Количество 12
Количество 12
GHSA-9mc4-rqmq-h467
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
CVE-2026-11940
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
CVE-2026-11940
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
CVE-2026-11940
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
CVE-2026-11940
tarfile.extractall() with the 'data' or 'tar' filter could be bypasse ...
RLSA-2026:54268
Important: python3.9 security update
ELSA-2026-54268
ELSA-2026-54268: python3.9 security update (IMPORTANT)
SUSE-SU-2026:3245-1
Security update for python3
SUSE-SU-2026:3569-1
Security update for python312
SUSE-SU-2026:3560-1
Security update for python311
SUSE-SU-2026:3548-1
Security update for python311
SUSE-SU-2026:3530-1
Security update for python310
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-9mc4-rqmq-h467 tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330. | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-11940 tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330. | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-11940 tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330. | CVSS3: 7.3 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-11940 tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330. | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-11940 tarfile.extractall() with the 'data' or 'tar' filter could be bypasse ... | 1% Низкий | около 2 месяцев назад | ||
RLSA-2026:54268 Important: python3.9 security update | 1% Низкий | 6 дней назад | ||
ELSA-2026-54268 ELSA-2026-54268: python3.9 security update (IMPORTANT) | 1% Низкий | 7 дней назад | ||
SUSE-SU-2026:3245-1 Security update for python3 | 26 дней назад | |||
SUSE-SU-2026:3569-1 Security update for python312 | 8 дней назад | |||
SUSE-SU-2026:3560-1 Security update for python311 | 9 дней назад | |||
SUSE-SU-2026:3548-1 Security update for python311 | 9 дней назад | |||
SUSE-SU-2026:3530-1 Security update for python310 | 12 дней назад |
Уязвимостей на страницу