{"id":"UBUNTU-CVE-2026-7774","details":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process.","modified":"2026-07-06T16:00:52.804467744Z","published":"2026-06-04T16:16:00Z","related":["USN-8509-1"],"upstream":["CVE-2026-7774"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-7774"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-7774"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2026/06/04/9"},{"type":"REPORT","url":"https://github.com/python/cpython/pull/149487"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8509-1"}],"affected":[{"package":{"name":"pypy3","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/pypy3?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.1.1+dfsg-1","7.2.0+dfsg-1","7.3.0+dfsg-1","7.3.0+dfsg-1ubuntu2","7.3.0+dfsg-1ubuntu3","7.3.1+dfsg-4","7.3.1+dfsg-4ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"pypy3","binary_version":"7.3.1+dfsg-4ubuntu0.1"},{"binary_version":"7.3.1+dfsg-4ubuntu0.1","binary_name":"pypy3-lib"},{"binary_name":"pypy3-lib-testsuite","binary_version":"7.3.1+dfsg-4ubuntu0.1"},{"binary_name":"pypy3-tk","binary_version":"7.3.1+dfsg-4ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"pypy3","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/pypy3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.3.5+dfsg-2","7.3.7+dfsg-1","7.3.7+dfsg-4","7.3.7+dfsg-5","7.3.8+dfsg-2","7.3.9+dfsg-1","7.3.9+dfsg-1ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_version":"7.3.9+dfsg-1ubuntu0.1","binary_name":"pypy3"},{"binary_name":"pypy3-lib","binary_version":"7.3.9+dfsg-1ubuntu0.1"},{"binary_version":"7.3.9+dfsg-1ubuntu0.1","binary_name":"pypy3-lib-testsuite"},{"binary_version":"7.3.9+dfsg-1ubuntu0.1","binary_name":"pypy3-tk"},{"binary_version":"7.3.9+dfsg-1ubuntu0.1","binary_name":"pypy3-venv"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"pypy3","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/pypy3?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.3.12+dfsg-1","7.3.13+dfsg-1","7.3.14+dfsg-1","7.3.15+dfsg-1","7.3.15+dfsg-1build2","7.3.15+dfsg-1build3"],"ecosystem_specific":{"binaries":[{"binary_version":"7.3.15+dfsg-1build3","binary_name":"pypy3"},{"binary_name":"pypy3-lib","binary_version":"7.3.15+dfsg-1build3"},{"binary_name":"pypy3-lib-testsuite","binary_version":"7.3.15+dfsg-1build3"},{"binary_name":"pypy3-tk","binary_version":"7.3.15+dfsg-1build3"},{"binary_name":"pypy3-venv","binary_version":"7.3.15+dfsg-1build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"python3.12","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/python3.12?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.12.3-1ubuntu0.15"}]}],"versions":["3.12.0-1","3.12.0-5","3.12.0-6","3.12.0-7","3.12.1-2","3.12.2-1","3.12.2-4build3","3.12.2-4build4","3.12.2-5ubuntu3","3.12.3-1","3.12.3-1ubuntu0.1","3.12.3-1ubuntu0.2","3.12.3-1ubuntu0.3","3.12.3-1ubuntu0.4","3.12.3-1ubuntu0.5","3.12.3-1ubuntu0.6","3.12.3-1ubuntu0.7","3.12.3-1ubuntu0.8","3.12.3-1ubuntu0.9","3.12.3-1ubuntu0.10","3.12.3-1ubuntu0.11","3.12.3-1ubuntu0.12","3.12.3-1ubuntu0.13"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"idle-python3.12","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"libpython3.12-minimal","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"libpython3.12-stdlib","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"libpython3.12-testsuite","binary_version":"3.12.3-1ubuntu0.15"},{"binary_version":"3.12.3-1ubuntu0.15","binary_name":"libpython3.12t64"},{"binary_name":"python3.12","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"python3.12-examples","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"python3.12-full","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"python3.12-minimal","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"python3.12-nopie","binary_version":"3.12.3-1ubuntu0.15"},{"binary_name":"python3.12-venv","binary_version":"3.12.3-1ubuntu0.15"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"pypy3","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/pypy3?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.3.19+dfsg-1","7.3.19+dfsg-2","7.3.20+dfsg-1","7.3.20+dfsg-3"],"ecosystem_specific":{"binaries":[{"binary_name":"pypy3","binary_version":"7.3.20+dfsg-3"},{"binary_name":"pypy3-lib","binary_version":"7.3.20+dfsg-3"},{"binary_name":"pypy3-lib-testsuite","binary_version":"7.3.20+dfsg-3"},{"binary_name":"pypy3-tk","binary_version":"7.3.20+dfsg-3"},{"binary_name":"pypy3-venv","binary_version":"7.3.20+dfsg-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"python3.13","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/python3.13?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.13.3-1","3.13.3-2","3.13.3-4","3.13.4-1","3.13.5-1","3.13.5-2","3.13.6-1","3.13.7-1","3.13.7-1ubuntu0.1","3.13.7-1ubuntu0.2","3.13.7-1ubuntu0.3","3.13.7-1ubuntu0.4"],"ecosystem_specific":{"binaries":[{"binary_version":"3.13.7-1ubuntu0.4","binary_name":"idle-python3.13"},{"binary_name":"libpython3.13","binary_version":"3.13.7-1ubuntu0.4"},{"binary_name":"libpython3.13-minimal","binary_version":"3.13.7-1ubuntu0.4"},{"binary_version":"3.13.7-1ubuntu0.4","binary_name":"libpython3.13-stdlib"},{"binary_name":"libpython3.13-testsuite","binary_version":"3.13.7-1ubuntu0.4"},{"binary_name":"python3.13","binary_version":"3.13.7-1ubuntu0.4"},{"binary_name":"python3.13-examples","binary_version":"3.13.7-1ubuntu0.4"},{"binary_version":"3.13.7-1ubuntu0.4","binary_name":"python3.13-full"},{"binary_version":"3.13.7-1ubuntu0.4","binary_name":"python3.13-gdbm"},{"binary_version":"3.13.7-1ubuntu0.4","binary_name":"python3.13-minimal"},{"binary_name":"python3.13-nopie","binary_version":"3.13.7-1ubuntu0.4"},{"binary_version":"3.13.7-1ubuntu0.4","binary_name":"python3.13-tk"},{"binary_name":"python3.13-venv","binary_version":"3.13.7-1ubuntu0.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"python3.14","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/python3.14?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.14.0~a7-0ubuntu1","3.14.0~b1-1","3.14.0~b3-1","3.14.0~rc1-1","3.14.0~rc2-1","3.14.0~rc3-1","3.14.0-1","3.14.0-1ubuntu0.1","3.14.0-1ubuntu0.2","3.14.0-1ubuntu0.3"],"ecosystem_specific":{"binaries":[{"binary_name":"idle-python3.14","binary_version":"3.14.0-1ubuntu0.3"},{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"libpython3.14"},{"binary_name":"libpython3.14-minimal","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"libpython3.14-stdlib","binary_version":"3.14.0-1ubuntu0.3"},{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"libpython3.14-testsuite"},{"binary_name":"python3.14","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"python3.14-examples","binary_version":"3.14.0-1ubuntu0.3"},{"binary_version":"3.14.0-1ubuntu0.3","binary_name":"python3.14-full"},{"binary_name":"python3.14-gdbm","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"python3.14-minimal","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"python3.14-nopie","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"python3.14-tk","binary_version":"3.14.0-1ubuntu0.3"},{"binary_name":"python3.14-venv","binary_version":"3.14.0-1ubuntu0.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"pypy3","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/pypy3?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.3.20+dfsg-3","7.3.20+dfsg-4"],"ecosystem_specific":{"binaries":[{"binary_version":"7.3.20+dfsg-4","binary_name":"pypy3"},{"binary_name":"pypy3-lib","binary_version":"7.3.20+dfsg-4"},{"binary_name":"pypy3-lib-testsuite","binary_version":"7.3.20+dfsg-4"},{"binary_version":"7.3.20+dfsg-4","binary_name":"pypy3-tk"},{"binary_name":"pypy3-venv","binary_version":"7.3.20+dfsg-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}},{"package":{"name":"python3.14","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/python3.14?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.14.4-1ubuntu0.1"}]}],"versions":["3.14.0-1","3.14.0-2","3.14.0-4","3.14.2-1","3.14.3-1","3.14.3-2","3.14.3-3","3.14.3-5","3.14.4-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"idle-python3.14","binary_version":"3.14.4-1ubuntu0.1"},{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"libpython3.14"},{"binary_version":"3.14.4-1ubuntu0.1","binary_name":"libpython3.14-minimal"},{"binary_name":"libpython3.14-stdlib","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"libpython3.14-testsuite","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-examples","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-full","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-gdbm","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-minimal","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-nopie","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-tk","binary_version":"3.14.4-1ubuntu0.1"},{"binary_name":"python3.14-venv","binary_version":"3.14.4-1ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-7774.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}