mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-09 17:03:35 -09:00
CVE-2026-0864: https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/ CVE-2026-11972: https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/ CVE-2026-4360: https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/ CVE-2026-15308: https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/ Signed-off-by: Bernd Kuhls <bernd@kuhls.net> Signed-off-by: Julien Olivain <ju.o@free.fr>
77 lines
3.0 KiB
Diff
77 lines
3.0 KiB
Diff
From e86666c9dd256d52d0fbef6feb1ea4a51768fdec Mon Sep 17 00:00:00 2001
|
|
From: "Miss Islington (bot)"
|
|
<31488909+miss-islington@users.noreply.github.com>
|
|
Date: Tue, 23 Jun 2026 15:46:18 +0200
|
|
Subject: [PATCH] [3.14] gh-151981: Make tarfile._Stream.seek break at EOF
|
|
(GH-151982) (#151992)
|
|
|
|
(cherry picked from commit f50bf13566189c8d0ce5a814f33eff3d89951896)
|
|
|
|
Co-authored-by: Petr Viktorin <encukou@gmail.com>
|
|
Co-authored-by: Stan Ulbrych <stan@python.org>
|
|
|
|
Upstream: https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec
|
|
CVE: CVE-2026-11972
|
|
|
|
Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
|
|
---
|
|
Lib/tarfile.py | 4 +++-
|
|
Lib/test/test_tarfile.py | 16 ++++++++++++++++
|
|
...026-06-23-13-28-16.gh-issue-151981.xBHEcU.rst | 2 ++
|
|
3 files changed, 21 insertions(+), 1 deletion(-)
|
|
create mode 100644 Misc/NEWS.d/next/Security/2026-06-23-13-28-16.gh-issue-151981.xBHEcU.rst
|
|
|
|
diff --git a/Lib/tarfile.py b/Lib/tarfile.py
|
|
index e6734db24f6..39b1cd6514c 100644
|
|
--- a/Lib/tarfile.py
|
|
+++ b/Lib/tarfile.py
|
|
@@ -524,7 +524,9 @@ def seek(self, pos=0):
|
|
if pos - self.pos >= 0:
|
|
blocks, remainder = divmod(pos - self.pos, self.bufsize)
|
|
for i in range(blocks):
|
|
- self.read(self.bufsize)
|
|
+ data = self.read(self.bufsize)
|
|
+ if not data:
|
|
+ break
|
|
self.read(remainder)
|
|
else:
|
|
raise StreamError("seeking backwards is not allowed")
|
|
diff --git a/Lib/test/test_tarfile.py b/Lib/test/test_tarfile.py
|
|
index d974c7d46ec..8503024a690 100644
|
|
--- a/Lib/test/test_tarfile.py
|
|
+++ b/Lib/test/test_tarfile.py
|
|
@@ -4762,6 +4762,22 @@ def valueerror_filter(tarinfo, path):
|
|
with self.check_context(arc.open(errorlevel='boo!'), filtererror_filter):
|
|
self.expect_exception(TypeError) # errorlevel is not int
|
|
|
|
+ @support.subTests('format', [tarfile.GNU_FORMAT, tarfile.PAX_FORMAT])
|
|
+ def test_getmembers_big_size(self, format):
|
|
+ # gh-151981: A loop in seek() for streaming files tried to read the
|
|
+ # declared number of blocks even at EOF
|
|
+ tinfo = tarfile.TarInfo("huge-file")
|
|
+ tinfo.size = 1 << 64
|
|
+ bio = io.BytesIO()
|
|
+ # Write header without data
|
|
+ bio.write(tinfo.tobuf(format))
|
|
+
|
|
+ # Reset & try to get contents
|
|
+ bio.seek(0)
|
|
+ with tarfile.open(fileobj=bio, mode="r|") as tar:
|
|
+ with self.assertRaises(tarfile.ReadError):
|
|
+ tar.getmembers()
|
|
+
|
|
|
|
class OverwriteTests(archiver_tests.OverwriteTests, unittest.TestCase):
|
|
testdir = os.path.join(TEMPDIR, "testoverwrite")
|
|
diff --git a/Misc/NEWS.d/next/Security/2026-06-23-13-28-16.gh-issue-151981.xBHEcU.rst b/Misc/NEWS.d/next/Security/2026-06-23-13-28-16.gh-issue-151981.xBHEcU.rst
|
|
new file mode 100644
|
|
index 00000000000..2123ab8e081
|
|
--- /dev/null
|
|
+++ b/Misc/NEWS.d/next/Security/2026-06-23-13-28-16.gh-issue-151981.xBHEcU.rst
|
|
@@ -0,0 +1,2 @@
|
|
+In :mod:`tarfile`, seeking a stream now stops when end of the stream is
|
|
+reached.
|
|
--
|
|
2.47.3
|
|
|