#1141531 pypy3: CVE-2026-4360

Package:
src:pypy3
Source:
src:pypy3
Submitter:
Moritz Mühlenhoff
Date:
2026-09-05 16:33:02 UTC
Severity:
normal
Tags:
#1141531#5
Date:
2026-07-05 20:35:47 UTC
From:
To:
Hi,

The following vulnerability was published for pypy3.

CVE-2026-4360[0]:
| In the Tarfile.extract() function, the filter parameter is not
| passed properly when extracting hardlinks. An affected system that
| extracts content from untrusted tar files could end up writing files
| with an unexpected uid/gid despite the user passing filter='data' to
| the extract() function.

https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/
https://github.com/python/cpython/issues/151987
https://github.com/python/cpython/pull/151988
https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301 (3.15 branch)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-4360
https://www.cve.org/CVERecord?id=CVE-2026-4360

Please adjust the affected versions in the BTS as needed.

#1141531#12
Date:
2026-09-05 16:32:06 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python3.13, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141531@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Mühlenhoff <jmm@debian.org> (supplier of updated python3.13 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 10 Aug 2026 14:06:59 +0200
Source: python3.13
Architecture: source
Version: 3.13.5-2+deb13u5
Distribution: trixie
Urgency: medium
Maintainer: Matthias Klose <doko@debian.org>
Changed-By: Moritz Mühlenhoff <jmm@debian.org>
Closes: 1141524 1141531 1141533 1141534
Changes:
 python3.13 (3.13.5-2+deb13u5) trixie; urgency=medium
 .
   * CVE-2026-6879
   * CVE-2026-0864 (Closes: #1141524)
   * CVE-2026-4360 (Closes: #1141531)
   * CVE-2026-11940 (Closes: #1141533)
   * CVE-2026-11972 (Closes: #1141534)
Checksums-Sha1:
 c6d5fe11260ea54c96caeda6dbf817983980fff0 4298 python3.13_3.13.5-2+deb13u5.dsc
 412b8df93c26d980ddcb4407728ec93504a898fa 299640 python3.13_3.13.5-2+deb13u5.debian.tar.xz
Checksums-Sha256:
 4be84e20fb902354fa86955e2fbea6e8bdbd158f54833423488308a9b3532662 4298 python3.13_3.13.5-2+deb13u5.dsc
 a51f456e654ce2c9b40cc1db8005e5041cdb0b2c3aa96ab0871c49fe95280366 299640 python3.13_3.13.5-2+deb13u5.debian.tar.xz
Files:
 d8bba168e3c3dce76ecddeed76d9dc3a 4298 python optional python3.13_3.13.5-2+deb13u5.dsc
 3c05432fbc5501a90208f9efd06f6e8c 299640 python optional python3.13_3.13.5-2+deb13u5.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqay4oACgkQEMKTtsN8
TjYvVA/+JIvNeFaT9Ncg+iOE4ARiP4u6HZXEALCGYCvYEGdVaAY5HT5Q07tXxP2/
C5R83aLlnrjZ4i9nICz6lmhtszNVfrd9cuI8sfvraTPnWA/PMiIVOsaIao+WJr3e
Nh+SdPzdMq/SzCMrypCcO1osmykC6M9vF560wyp+OQnUxernAVTO6706yFeqIAAE
WcfQO9jWqxzHpP1vgrUxpANE67ibnOXHTv4g6vsHj1G3GaXPv+a0tzDFRr7+Axwj
JgXR1C4gEj5lPsBdanOKtykzBf5yg88v7xDWmONX6S0chSuY2jiSpMGO983++akd
a/ovIsD4pUWUueYzYb3FVF4tEu224oD+BwOUxExtk/ymU5Wqnd0jgxAmi1ssJyNQ
DgxkOtxPpgGB1YtRuqCrlbUCPfyiARd5897J8JrTPCm2k1ZI+TZNcl/t8WYeRU48
MyHgh5l32Orq1fPwmZIr4t5iwhEur+PS5VjyU2G9XsEX+cdU6qGh+QUlWnpk4aC4
09sBYODyemyiYUqpHxKu2HI6WWJkWf0pNs+kGTCINr5xYS4BW+jd6L6AjacHEgDm
Mk9FIteUnzUlxVHGY2f9qeTQ4XIOyx9dweKGboYn771riaY9SY2BU48QyrcDmhn4
mrdV52xpn/gtZAQEXAwzQVIfAtv9Uj6e+ryisEP0bahEZTR6cIU=
=CTkN
-----END PGP SIGNATURE-----