python3-3.6.8-21.0.5.0.2.el7.AXS7

エラータID: AXSA:2025-11111:08

Release date: 
Wednesday, November 26, 2025 - 17:15
Subject: 
python3-3.6.8-21.0.5.0.2.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Python is an accessible, high-level, dynamically typed, interpreted programming
language, designed with an emphasis on code readability.
It includes an extensive standard library, and has a vast ecosystem of
third-party libraries.

The python3 package provides the "python3" executable: the reference
interpreter for the Python language, version 3.
The majority of its standard library is provided in the python3-libs package,
which should be installed automatically along with python3.
The remaining parts of the Python standard library are broken out into the
python3-tkinter and python3-test packages, which may need to be installed
separately.

Documentation for Python is provided in the python3-docs package.

Packages containing additional libraries for Python are generally named with
the "python3-" prefix.

Security Fix(es):

* CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435, CVE-2025-4517:
fix multiple tarfile extraction filter bypasses (filter="tar"/filter="data")

CVE(s):
CVE-2025-4435
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
CVE-2024-12718
Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
CVE-2025-4517
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
CVE-2025-4330
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.
CVE-2025-4138
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

Asianux Server 7 for x86_64
  1. python3-3.6.8-21.0.5.0.2.el7.AXS7.i686.rpm
    MD5: 958cb89f62e28b8418f03693818883b1
    SHA-256: 81a4851d6b0e65b81dbb855d7d6d85ed56e63e6c1442b22d2a0e63b40d77ecc4
    Size: 72.20 kB
  2. python3-3.6.8-21.0.5.0.2.el7.AXS7.x86_64.rpm
    MD5: 168e70554eb108b704eb1d88def6c119
    SHA-256: 17003d6d421d9715362bff2bd7d2dd5fcb606b824c9e5d98168a623056408df5
    Size: 72.14 kB
  3. python3-debug-3.6.8-21.0.5.0.2.el7.AXS7.i686.rpm
    MD5: 00dfb8847a763417102a142c905eb1b5
    SHA-256: 1923ec7211902576053461fdc65310f0ccad074b5c754850324d65e1876ae883
    Size: 2.42 MB
  4. python3-debug-3.6.8-21.0.5.0.2.el7.AXS7.x86_64.rpm
    MD5: 86f18886d435b724fdd1ae9a2af3d91e
    SHA-256: 6980b67fdad9963f85e3b91c846d376b82face9a3224bd5b0b596887416fc4a4
    Size: 2.64 MB
  5. python3-devel-3.6.8-21.0.5.0.2.el7.AXS7.i686.rpm
    MD5: b2d8e4b06e579e7b23819da7524a2303
    SHA-256: 55342e01ad442ec3f7aaf5506ef920694f4ceff4ac47525abb486dcd80542565
    Size: 219.02 kB
  6. python3-devel-3.6.8-21.0.5.0.2.el7.AXS7.x86_64.rpm
    MD5: a0b8c9aabd22e96c548a7d08a6c227b6
    SHA-256: 255706582f07febb4d7fda847a467c061796abbbbfd184f38e1efd722ba452e3
    Size: 218.83 kB
  7. python3-idle-3.6.8-21.0.5.0.2.el7.AXS7.i686.rpm
    MD5: 86f09f7357515567feb2bf9a9f69f939
    SHA-256: e901fc0a9b7eb36920dd2a0af7809f099ce75abc44040e9e0d4b8bcb208a2af2
    Size: 781.28 kB
  8. python3-idle-3.6.8-21.0.5.0.2.el7.AXS7.x86_64.rpm
    MD5: aa21b115d48af85797df9a7bb2c917f2
    SHA-256: c9a6bcf4eb235ba00231a7938e6c5a1cc1813546dec66261e63c28b55c9b2ada
    Size: 781.23 kB
  9. python3-libs-3.6.8-21.0.5.0.2.el7.AXS7.i686.rpm
    MD5: 2a3c8ae4225b3f04cfb13155196a5fbd
    SHA-256: 316cc6b6fc30a964c17b4fe319ded12039cfe2646a673c7101b75c8b581c7587
    Size: 6.86 MB
  10. python3-libs-3.6.8-21.0.5.0.2.el7.AXS7.x86_64.rpm
    MD5: 1dc72ac77667b408fa4a4e1bce220506
    SHA-256: c7d71ababca274a770fb575ed33a24e1202d5407fbfb11c0aad5311c3d034e28
    Size: 6.96 MB
  11. python3-test-3.6.8-21.0.5.0.2.el7.AXS7.i686.rpm
    MD5: 32c8110597adacad2ab06c21a20afc27
    SHA-256: f92d1345926887b7fbf824736f1627348e37b3a3fe7d477c5ff0152090808d71
    Size: 7.29 MB
  12. python3-test-3.6.8-21.0.5.0.2.el7.AXS7.x86_64.rpm
    MD5: 230e0242659af1918a5b2fa65b648fab
    SHA-256: 7ab8299127a69137b029748a2e56f84b678b0489c0544e7cfa5bf1d15efd8061
    Size: 7.29 MB
  13. python3-tkinter-3.6.8-21.0.5.0.2.el7.AXS7.i686.rpm
    MD5: 32d72d2862c3622cc5cd3a9a99315188
    SHA-256: 28ef95823ef0a773e32bf0df2cf0170bd007ae038d0286970ec6b41dcbdce5f5
    Size: 367.54 kB
  14. python3-tkinter-3.6.8-21.0.5.0.2.el7.AXS7.x86_64.rpm
    MD5: b10d6f035671c2f96a77b7e0ab28c1bb
    SHA-256: 7febe8da243efbc3239eef8219691ec0dc13817a78d0f9a3383991a73e94e6a4
    Size: 367.50 kB