The vendor explicitly identifies these products or versions as containing the fix.
- python3-10-main@aarch64 as a component of Red Hat Hardened Images
- python3-10-main@src as a component of Red Hat Hardened Images
- python3-10-main@x86_64 as a component of Red Hat Hardened Images
- python3-11-main@aarch64 as a component of Red Hat Hardened Images
- python3-11-main@src as a component of Red Hat Hardened Images
- python3-11-main@x86_64 as a component of Red Hat Hardened Images
- python3-12-main@aarch64 as a component of Red Hat Hardened Images
- python3-12-main@src as a component of Red Hat Hardened Images
- python3-12-main@x86_64 as a component of Red Hat Hardened Images
- python3-13-main@aarch64 as a component of Red Hat Hardened Images
- python3-13-main@src as a component of Red Hat Hardened Images
- python3-13-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw was found in the Python `tarfile` module. This vulnerability allows an attacker to create empty directories outside of the intended extraction destination on POSIX (Portable Operating System Interface) platforms. This occurs when processing a specially crafted archive containing member names that use directory traversal sequences (e.g., `../`) to leave and then re-enter the target directory. While only empty directories are created outside the destination, this can lead to unintended file system modifications.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
