Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
cf0b36ff by Sylvain Beucler at 2026-07-13T13:01:24+02:00
CVE-2026-4360: python3.11,python3.9,python2.7,jython not-affected, pypy3 
postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8404,23 +8404,21 @@ CVE-2026-4360 (In the Tarfile.extract() function, the 
filter parameter is not pa
        - python3.14 <unfixed>
        - python3.13 <unfixed>
        [trixie] - python3.13 <no-dsa> (Minor issue)
-       - python3.11 <removed>
-       - python3.9 <removed>
-       [bullseye] - python3.9 <not-affected> (extraction filters (PEP 706) 
absent in 3.9.2; extract() has no filter parameter)
-       - python2.7 <removed>
-       [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
-       - jython <unfixed>
-       [trixie] - jython <no-dsa> (Minor issue)
-       [bookworm] - jython <not-affected> (extraction filters/PEP 706 absent 
in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
-       [bullseye] - jython <end-of-life> (EOL in bullseye LTS)
+       - python3.11 <not-affected> (Vulnerable code didn't get backported to 
the version in Bookworm)
+       - python3.9 <not-affected> (extraction filters (PEP 706) absent in 
3.9.2; extract() has no filter parameter)
+       - python2.7 <not-affected> (extraction filters (PEP 706) absent in py2; 
extract() has no filter parameter)
+       - jython <not-affected> (extraction filters/PEP 706 absent in bundled 
python2.7 stdlib; tarfile.extract() has no filter parameter)
        - pypy3 <unfixed> (bug #1141531)
        [trixie] - pypy3 <no-dsa> (Minor issue)
+       [bookworm] - pypy3 <postponed> (Minor issue)
+       [bullseye] - pypy3 <postponed> (Minor issue)
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/
        NOTE: https://github.com/python/cpython/issues/151987
        NOTE: https://github.com/python/cpython/pull/151988
        NOTE: 
https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301
 (3.15 branch)
        NOTE: 
https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0
 (3.14 branch)
        NOTE: 
https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e
 (3.13 branch)
+       NOTE: Same code situation as with CVE-2025-4435.
 CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ.  An 
authentic ...)
        - activemq <unfixed> (bug #1141385)
        NOTE: https://lists.apache.org/thread/w82vtc3q02j5ot94tnyy1197y3wb98hl



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf0b36ff7e7fa5cc90ad136db01125b78392d169

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf0b36ff7e7fa5cc90ad136db01125b78392d169
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to