Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
cf0b36ff by Sylvain Beucler at 2026-07-13T13:01:24+02:00
CVE-2026-4360: python3.11,python3.9,python2.7,jython not-affected, pypy3
postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -8404,23 +8404,21 @@ CVE-2026-4360 (In the Tarfile.extract() function, the
filter parameter is not pa
- python3.14 <unfixed>
- python3.13 <unfixed>
[trixie] - python3.13 <no-dsa> (Minor issue)
- - python3.11 <removed>
- - python3.9 <removed>
- [bullseye] - python3.9 <not-affected> (extraction filters (PEP 706)
absent in 3.9.2; extract() has no filter parameter)
- - python2.7 <removed>
- [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- - jython <unfixed>
- [trixie] - jython <no-dsa> (Minor issue)
- [bookworm] - jython <not-affected> (extraction filters/PEP 706 absent
in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
- [bullseye] - jython <end-of-life> (EOL in bullseye LTS)
+ - python3.11 <not-affected> (Vulnerable code didn't get backported to
the version in Bookworm)
+ - python3.9 <not-affected> (extraction filters (PEP 706) absent in
3.9.2; extract() has no filter parameter)
+ - python2.7 <not-affected> (extraction filters (PEP 706) absent in py2;
extract() has no filter parameter)
+ - jython <not-affected> (extraction filters/PEP 706 absent in bundled
python2.7 stdlib; tarfile.extract() has no filter parameter)
- pypy3 <unfixed> (bug #1141531)
[trixie] - pypy3 <no-dsa> (Minor issue)
+ [bookworm] - pypy3 <postponed> (Minor issue)
+ [bullseye] - pypy3 <postponed> (Minor issue)
NOTE:
https://mail.python.org/archives/list/[email protected]/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/
NOTE: https://github.com/python/cpython/issues/151987
NOTE: https://github.com/python/cpython/pull/151988
NOTE:
https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301
(3.15 branch)
NOTE:
https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0
(3.14 branch)
NOTE:
https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e
(3.13 branch)
+ NOTE: Same code situation as with CVE-2025-4435.
CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ. An
authentic ...)
- activemq <unfixed> (bug #1141385)
NOTE: https://lists.apache.org/thread/w82vtc3q02j5ot94tnyy1197y3wb98hl
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf0b36ff7e7fa5cc90ad136db01125b78392d169
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf0b36ff7e7fa5cc90ad136db01125b78392d169
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits