Release Info

Advisory: CLSA-2025:1762529544

OS: EL 10

Public date: 2025-11-07 15:32:26.174749

Project: python

Version: 3.6.15-13.el10

Errata link: https://errata.tuxcare.com/els_alt_python/el10/CLSA-2025-1762529544.html

Changelog

- Fix CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435, CVE-2025-4517: fix multiple tarfile extraction filter bypasses (filter="tar"/filter="data") - fix test_tarfile.py

Update

Update command: yum update alt-python*

Packages list

alt-python36-3.6.15-13.el10.x86_64.rpm alt-python36-debug-3.6.15-13.el10.x86_64.rpm alt-python36-devel-3.6.15-13.el10.x86_64.rpm alt-python36-libs-3.6.15-13.el10.x86_64.rpm alt-python36-test-3.6.15-13.el10.x86_64.rpm alt-python36-tkinter-3.6.15-13.el10.x86_64.rpm alt-python36-tools-3.6.15-13.el10.x86_64.rpm

CVEs

CVE-2025-4330
CVE-2025-4435
CVE-2025-4138
CVE-2024-12718
CVE-2025-4517