Skip to content

[3.11] gh-130577: tarfile now validates archives to ensure member offsets are non-negative (GH-137027) #137172

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 19, 2025

Conversation

miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Jul 28, 2025

(cherry picked from commit 7040aa5)

Co-authored-by: Alexander Urieles aeurielesn@users.noreply.github.com
Co-authored-by: Gregory P. Smith greg@krypto.org

…ets are non-negative (pythonGH-137027)

(cherry picked from commit 7040aa5)

Co-authored-by: Alexander Urieles <aeurielesn@users.noreply.github.com>
Co-authored-by: Gregory P. Smith <greg@krypto.org>
@Kevin-Molina
Copy link

Kevin-Molina commented Aug 19, 2025

Howdy! Wondering if there's any ETA on this high CVE fix getting rolled out? Thank you!

CC: @pablogsal

@pablogsal pablogsal merged commit b4ec174 into python:3.11 Aug 19, 2025
27 checks passed
@pablogsal
Copy link
Member

pablogsal commented Aug 19, 2025

Howdy! Wondering if there's any ETA on this high CVE fix getting rolled out? Thank you!

We can coordinate a release with the rest of the RM team. Will check with them soon

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Development

Successfully merging this pull request may close these issues.

7 participants