tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
CVSS Details
- CVSS 4.0 Base Score: 7.8 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade python3 | Aug 17, 2026 | Jun 23, 2026 |
| Debian | — | Upgrade python3.13 | Sep 21, 2026 | Jun 23, 2026 |
| Redhat_linux | — | Upgrade python3.9-debugsourceUpgrade python3.12-develUpgrade python3-libsUpgrade platform-python-develUpgrade python3-tkinterUpgrade python3.14-freethreading-testUpgrade python3.9-debuginfoUpgrade python3.14-debugUpgrade python-unversioned-commandUpgrade python3.14Upgrade python3.12-rpm-macrosUpgrade python3.14-testUpgrade python3-idleUpgrade python3.14-freethreadingUpgrade python3-develUpgrade python3-debuginfoUpgrade python3-debugsourceUpgrade python3.14-freethreading-tkinterUpgrade platform-python-debugUpgrade python3.14-freethreading-idleUpgrade python3.14-libsUpgrade python3.14-freethreading-develUpgrade python3.14-freethreading-libsUpgrade python3.14-idleUpgrade python3.14-freethreading-debugUpgrade python3.14-debuginfoUpgrade python3.12-libsUpgrade python3.14-tkinterUpgrade python3.12-tkinterUpgrade python3.12-idleUpgrade python3.12-debugNo solution existsUpgrade python3Upgrade python3-debugUpgrade platform-pythonUpgrade python3.12-debugsourceUpgrade python3.12-testUpgrade python3.14-debugsourceUpgrade python3.12Upgrade python3.14-develUpgrade python3.12-debuginfoUpgrade python3-test | Aug 13, 2026 | Jun 23, 2026 |
| Rocky_linux | — | Upgrade python3.14-tkinterUpgrade python3.9-debuginfoUpgrade python3.14-debugUpgrade platform-python-develUpgrade python3-develUpgrade python3-debuginfoUpgrade python3-idleUpgrade python3-debugUpgrade python3.14-debuginfoUpgrade python3.14-freethreading-tkinterUpgrade python3.14-freethreading-idleUpgrade platform-python-debugUpgrade python3.12-debuginfoUpgrade python3-debugsourceUpgrade python3-libsUpgrade python3.14-debugsourceUpgrade python3.12Upgrade python3-tkinterUpgrade platform-pythonUpgrade python3.12-testUpgrade python3.9-debugsourceUpgrade python3.14-freethreading-develUpgrade python3.14-develUpgrade python3.12-develUpgrade python3.14-idleUpgrade python3.12-idleUpgrade python3.12-debugsourceUpgrade python3.14Upgrade python3.12-debugUpgrade python3-testUpgrade python3.14-testUpgrade python3Upgrade python3.12-libsUpgrade python3.12-tkinterUpgrade python3.14-freethreadingUpgrade python3.14-freethreading-testUpgrade python3.14-freethreading-debugUpgrade python3.14-freethreading-libsUpgrade python3.14-libs | Aug 14, 2026 | Aug 13, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2026 | Jun 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub