Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1c3b68c9 by Utkarsh Gupta at 2026-07-11T02:44:44+05:30
lts: python3.9 not-affected in bullseye (CVE-2026-4360)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7605,6 +7605,7 @@ CVE-2026-4360 (In the Tarfile.extract() function, the 
filter parameter is not pa
        [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
        - python3.9 <removed>
+       [bullseye] - python3.9 <not-affected> (extraction filters (PEP 706) 
absent in 3.9.2; extract() has no filter parameter)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
        - jython <unfixed>
@@ -7618,6 +7619,9 @@ CVE-2026-4360 (In the Tarfile.extract() function, the 
filter parameter is not pa
        NOTE: 
https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301
 (3.15 branch)
        NOTE: 
https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0
 (3.14 branch)
        NOTE: 
https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e
 (3.13 branch)
+       NOTE: [bullseye] python3.9 (3.9.2-1+deb11u7) predates the tarfile 
extraction filters
+       NOTE: (PEP 706, backported upstream in 3.9.17); extract()/extractall() 
have no filter
+       NOTE: parameter and Debian did not backport it, so the hardlink 
filter-bypass is not present.
 CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ.  An 
authentic ...)
        - activemq <unfixed> (bug #1141385)
        NOTE: https://lists.apache.org/thread/w82vtc3q02j5ot94tnyy1197y3wb98hl



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to