diff --git a/python3.11-3.11.6-CVE-2026-19672.patch b/python3.11-3.11.6-CVE-2026-19672.patch new file mode 100644 index 0000000000000000000000000000000000000000..2229e4009793b7541c92c20d8860eddfb74bfaad --- /dev/null +++ b/python3.11-3.11.6-CVE-2026-19672.patch @@ -0,0 +1,97 @@ +From 3ee68fa9516b9780d62cc17f68b0f359551c5ac1 Mon Sep 17 00:00:00 2001 +From: Stan Ulbrych +Date: Wed, 19 Aug 2026 09:52:01 +0100 +Subject: [PATCH] gh-155999: `tarfile`: handle a member that leaves the + destination but comes back (GH-156000) (cherry picked from commit + 97688346ada2df3e5b9c279348862c3d64ab0823) + +Co-authored-by: Stan Ulbrych +--- + Doc/library/tarfile.rst | 8 ++++++++ + Lib/tarfile.py | 7 +++++++ + Lib/test/test_tarfile.py | 14 ++++++++++++++ + .../2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst | 5 +++++ + 4 files changed, 34 insertions(+) + create mode 100644 Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst + + +diff --git a/Doc/library/tarfile.rst b/Doc/library/tarfile.rst +index 559cd5f..c278c01 100644 +--- a/Doc/library/tarfile.rst ++++ b/Doc/library/tarfile.rst +@@ -950,6 +950,10 @@ reused in custom filters: + paths (in case the name is absolute + even after stripping slashes, e.g. ``C:/foo`` on Windows). + This raises :class:`~tarfile.AbsolutePathError`. ++ - Normalize filenames (:attr:`TarInfo.name`) that contain ``..`` components ++ using :func:`os.path.normpath`. ++ Note that this removes internal ``..`` components, which may change the ++ meaning of the name if it traverses symbolic links. + - :ref:`Refuse ` to extract files whose absolute + path (after following symlinks) would end up outside the destination. + This raises :class:`~tarfile.OutsideDestinationError`. +@@ -958,6 +962,10 @@ reused in custom filters: + + Return the modified ``TarInfo`` member. + ++ .. versionchanged:: next ++ ++ Filenames containing ``..`` components are now normalized. ++ + .. function:: data_filter(member, path) + + Implements the ``'data'`` filter. +diff --git a/Lib/tarfile.py b/Lib/tarfile.py +index 66c39ec..1eebc74 100755 +--- a/Lib/tarfile.py ++++ b/Lib/tarfile.py +@@ -775,6 +775,13 @@ def _get_filtered_attrs(member, dest_path, for_data=True): + # For example, 'C:/foo' on Windows. + raise AbsolutePathError(member) + # Ensure we stay in the destination ++ if '..' in name.replace(os.sep, '/').split('/'): ++ # Directories are created from the name as given, so a name that ++ # leaves the destination part-way through would create them ++ # outside it even if the resolved path stays inside. ++ normalized = os.path.normpath(name) ++ if normalized != name: ++ name = new_attrs['name'] = normalized + target_path = os.path.realpath(os.path.join(dest_path, name), + strict=os.path.ALLOW_MISSING) + if os.path.commonpath([target_path, dest_path]) != dest_path: +diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py +index d8330c8..ad1b631 100644 +--- a/Lib/test/test_tarfile.py ++++ b/Lib/test/test_tarfile.py +@@ -3538,6 +3538,20 @@ class TestExtractionFilters(unittest.TestCase): + tarfile.AbsolutePathError, + """['"].*escaped.evil['"] has an absolute path""") + ++ def test_parent_dir_out_and_back(self): ++ # Test a member that leaves the destination and comes back. ++ # The containment check looks at the resolved path, which stays ++ # inside, but the intermediate directories are created from the ++ # name as given, which does not. ++ with ArchiveMaker() as arc: ++ arc.add(f'../escaped.evil/../{self.destdir.name}/sub/file', ++ content='content') ++ ++ for filter in 'tar', 'data': ++ with self.subTest(filter): ++ with self.check_context(arc.open(), filter): ++ self.expect_file('sub/file', content='content') ++ + @symlink_test + def test_parent_symlink(self): + # Test interplaying symlinks +diff --git a/Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst b/Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst +new file mode 100644 +index 0000000..59b725e +--- /dev/null ++++ b/Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst +@@ -0,0 +1,5 @@ ++Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating ++directories outside the destination for members whose name leaves the ++destination and returns to it, such as ``../evil/../dest/sub/file``. The ++containment check used the resolved path, but intermediate directories were ++created from the name as given. diff --git a/python3.11.spec b/python3.11.spec index 1fde76a902252e57a9af6f35d3d51a337dfd5824..602ad269b77e61b01879a0078c045edf79022c97 100644 --- a/python3.11.spec +++ b/python3.11.spec @@ -64,7 +64,7 @@ Summary: Version %{pybasever} of the Python interpreter Name: python%{pybasever} Version: %{src_version} -Release: 32%{?dist} +Release: 33%{?dist} License: Python-2.0.1 URL: https://www.python.org/ @@ -131,6 +131,7 @@ Patch0050: CVE-2026-0865-3.11-gh-143916-Reject-control-characters-in-wsgiref..pa Patch0051: CVE-2026-1299-3.11-gh-144125-email-verify-headers-are-sound-in-Byt.patch Patch0052: CVE-2026-18503-3.11-gh-98820-Fix-quadratic-time-in-csv.Sniffer.patch Patch0053: CVE-2026-11940.patch +Patch0054: python3.11-3.11.6-CVE-2026-19672.patch Patch3000: 00001-rpath.patch Patch3001: 00251-change-user-install-location.patch @@ -1164,6 +1165,10 @@ LD_LIBRARY_PATH=$(pwd)/normal $(pwd)/normal/python -m test.regrtest \ %endif %changelog +* Fri Oct 09 2026 PkgAgent Robot - 3.11.6-33 +- [Type] security +- [DESC] Fix CVE-2026-19672: tarfile tar/data filters create dirs outside destination when member name leaves and returns + * Wed Aug 12 2026 PkgAgent Robot - 3.11.6-32 - [Type] security - [DESC] Fix CVE-2026-11940: tarfile data/tar extraction filter symlink escape via hardlink fallback