mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
package/python3: add upstream security patch for CVE-2026-11940
https://seclists.org/oss-sec/2026/q2/1006 https://www.cve.org/CVERecord?id=CVE-2026-11940 https://github.com/python/cpython/pull/151559 Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
This commit is contained in:
@@ -0,0 +1,83 @@
|
||||
From 79c06bd5c6afa3c440d50faf7ee1b147c8832b4c Mon Sep 17 00:00:00 2001
|
||||
From: "Miss Islington (bot)"
|
||||
<31488909+miss-islington@users.noreply.github.com>
|
||||
Date: Tue, 23 Jun 2026 15:58:47 +0200
|
||||
Subject: [PATCH] [3.14] gh-151558: Fix symlink escape via `tarfile`
|
||||
hardlink-extraction fallback (GH-151559)
|
||||
|
||||
(cherry picked from commit 27dd970bf6b17ebca7c8ed486a40ab043ed7af8f)
|
||||
|
||||
Co-authored-by: Stan Ulbrych <stan@python.org>
|
||||
|
||||
Upstream: https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c
|
||||
CVE: CVE-2026-11940
|
||||
|
||||
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
|
||||
---
|
||||
Lib/tarfile.py | 3 +++
|
||||
Lib/test/test_tarfile.py | 24 +++++++++++++++++++
|
||||
...-06-10-13-08-19.gh-issue-151558.mL74i2.rst | 3 +++
|
||||
3 files changed, 30 insertions(+)
|
||||
create mode 100644 Misc/NEWS.d/next/Security/2026-06-10-13-08-19.gh-issue-151558.mL74i2.rst
|
||||
|
||||
diff --git a/Lib/tarfile.py b/Lib/tarfile.py
|
||||
index 39b1cd6514c..399f906efdf 100644
|
||||
--- a/Lib/tarfile.py
|
||||
+++ b/Lib/tarfile.py
|
||||
@@ -2784,6 +2784,9 @@ def makelink_with_filter(self, tarinfo, targetpath,
|
||||
"makelink_with_filter: if filter_function is not None, "
|
||||
+ "extraction_root must also not be None")
|
||||
try:
|
||||
+ filter_function(
|
||||
+ unfiltered.replace(name=tarinfo.name, deep=False),
|
||||
+ extraction_root)
|
||||
filtered = filter_function(unfiltered, extraction_root)
|
||||
except _FILTER_ERRORS as cause:
|
||||
raise LinkFallbackError(tarinfo, unfiltered.name) from cause
|
||||
diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py
|
||||
index 8503024a690..045377d620c 100644
|
||||
--- a/Lib/test/test_tarfile.py
|
||||
+++ b/Lib/test/test_tarfile.py
|
||||
@@ -4344,6 +4344,30 @@ def test_sneaky_hardlink_fallback(self):
|
||||
self.expect_file("boom", symlink_to='../../link_here')
|
||||
self.expect_file("c", symlink_to='b')
|
||||
|
||||
+ @symlink_test
|
||||
+ def test_sneaky_hardlink_fallback_deep(self):
|
||||
+ # (CVE-2026-11940)
|
||||
+ with ArchiveMaker() as arc:
|
||||
+ arc.add("a/b/s", symlink_to=os.path.join("..", "escape"))
|
||||
+ arc.add("s", hardlink_to=os.path.join("a", "b", "s"))
|
||||
+
|
||||
+ with self.check_context(arc.open(), 'data'):
|
||||
+ e = self.expect_exception(
|
||||
+ tarfile.LinkFallbackError,
|
||||
+ "link 's' would be extracted as a copy of "
|
||||
+ + "'a/b/s', which was rejected")
|
||||
+ self.assertIsInstance(e.__cause__,
|
||||
+ tarfile.LinkOutsideDestinationError)
|
||||
+
|
||||
+ for filter in 'tar', 'fully_trusted':
|
||||
+ with self.subTest(filter), self.check_context(arc.open(), filter):
|
||||
+ if not os_helper.can_symlink():
|
||||
+ self.expect_file("a/")
|
||||
+ self.expect_file("a/b/")
|
||||
+ else:
|
||||
+ self.expect_file("a/b/s", symlink_to=os.path.join('..', 'escape'))
|
||||
+ self.expect_file("s", symlink_to=os.path.join('..', 'escape'))
|
||||
+
|
||||
@symlink_test
|
||||
def test_exfiltration_via_symlink(self):
|
||||
# (CVE-2025-4138)
|
||||
diff --git a/Misc/NEWS.d/next/Security/2026-06-10-13-08-19.gh-issue-151558.mL74i2.rst b/Misc/NEWS.d/next/Security/2026-06-10-13-08-19.gh-issue-151558.mL74i2.rst
|
||||
new file mode 100644
|
||||
index 00000000000..74459d5680e
|
||||
--- /dev/null
|
||||
+++ b/Misc/NEWS.d/next/Security/2026-06-10-13-08-19.gh-issue-151558.mL74i2.rst
|
||||
@@ -0,0 +1,3 @@
|
||||
+Fixed an vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction
|
||||
+filters where crafted archives could create a symlink pointing outside the
|
||||
+destination directory. This was a bypass of :cve:`2025-4330`.
|
||||
--
|
||||
2.47.3
|
||||
|
||||
@@ -13,6 +13,9 @@ PYTHON3_LICENSE_FILES = LICENSE
|
||||
PYTHON3_CPE_ID_VENDOR = python
|
||||
PYTHON3_CPE_ID_PRODUCT = python
|
||||
|
||||
# 0011-3.14-gh-151558-Fix-symlink-escape-via-tarfile-hardli.patch
|
||||
PYTHON3_IGNORE_CVES += CVE-2026-11940
|
||||
|
||||
# This host Python is installed in $(HOST_DIR), as it is needed when
|
||||
# cross-compiling third-party Python modules.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user