In CPython 3.13 and earlier, the tarfile modules data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | python3-14-main-3.14.7-1.1.hum1 | * |
| Red Hat Hardened Images | RedHat | python3-10-main-3.10.21-1.3.hum1 | * |
| Red Hat Hardened Images | RedHat | python3-11-main-3.11.16-1.4.hum1 | * |
| Red Hat Hardened Images | RedHat | python3-12-main-3.12.14-1.3.hum1 | * |
| Red Hat Hardened Images | RedHat | python3-13-main-3.13.15-1.3.hum1 | * |