In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
CVSS Details
- CVSS 4.0 Base Score: 2 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade python3 | Aug 17, 2026 | Jun 30, 2026 |
| Amazon_linux_2023 | — | Upgrade python3.13-testUpgrade python3.12-develUpgrade python3.14Upgrade python3.14-debugUpgrade python3.13-freethreading-debugUpgrade python3.9-debuginfoUpgrade python3.9-debugsourceUpgrade python3.13-tkinterUpgrade python3-libsUpgrade python3.12-debugsourceUpgrade python3.13-debugUpgrade python3.13-freethreadingUpgrade python3-develUpgrade python3.14-freethreading-develUpgrade python3.13-libsUpgrade python-unversioned-commandUpgrade python3.14-testUpgrade python3.14-freethreadingUpgrade python3.13-idleUpgrade python3.12-testUpgrade python3.13-debugsourceUpgrade python3-idleUpgrade python3.14-freethreading-testUpgrade python3-tkinterUpgrade python3.14-freethreading-libsUpgrade python3.14-freethreading-debugUpgrade python3.13-develUpgrade python3.12-debugUpgrade python3.14-tkinterUpgrade python3.14-freethreading-idleUpgrade python3.14-debugsourceUpgrade python3.12-idleUpgrade python3.14-debuginfoUpgrade python3.12-libsUpgrade python3.14-libsUpgrade python3.14-freethreading-tkinterUpgrade python3Upgrade python3.12-tkinterUpgrade python3.13-debuginfoUpgrade python3-testUpgrade python3.14-idleUpgrade python3-debugUpgrade python3.12Upgrade python3.12-debuginfoUpgrade python3.13Upgrade python3.14-devel | Aug 10, 2026 | Jun 30, 2026 |
| Debian | — | Upgrade python3.13 | Sep 21, 2026 | Jun 30, 2026 |
| Redhat_linux | — | No solution exists | Jul 30, 2026 | Jun 30, 2026 |
| Ubuntu | — | Upgrade python3.4 (Ubuntu Pro)Upgrade python3.9 (Ubuntu Pro)Upgrade libpython3.5 (Ubuntu Pro)Upgrade python3.14Upgrade libpython3.10Upgrade libpython3.8 (Ubuntu Pro)Upgrade libpython3.4 (Ubuntu Pro)Upgrade python3.5 (Ubuntu Pro)Upgrade python3.7 (Ubuntu Pro)Upgrade python3.8 (Ubuntu Pro)Upgrade python3.11 (Ubuntu Pro)Upgrade libpython3.7 (Ubuntu Pro)Upgrade libpython3.14Upgrade python3.6 (Ubuntu Pro)Upgrade libpython2.7 (Ubuntu Pro)Upgrade python3.12Upgrade python2.7 (Ubuntu Pro)Upgrade libpython3.9 (Ubuntu Pro)Upgrade libpython3.6 (Ubuntu Pro)Upgrade python3.10Upgrade libpython3.11 (Ubuntu Pro)Upgrade libpython3.12t64 | Sep 14, 2026 | Sep 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub