VDB
RHSA-2025%3A13267
RHSA-2025%3A13267
PUBLISHED
CVSS 7.599999904632568 HIGH
A flaw was found in CPython's tarfile module. This vulnerability allows modification of file metadata, such as timestamps or permissions, outside the intended extraction directory via maliciously crafted tar archives using the filter="data" or filter="tar" extraction filters.
Risk Scores
CVSS 3.1
7.599999904632568
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/discovery/discovery-server-rhel9@sha256:ad07f55ee75fb20310c88f154a04665bd8465d138d66c665c300f61447858344_amd64 as a component of Red Hat Discovery 2 | registry.redhat.io/discovery/discovery-server-rhel9@sha256:ad07f55ee75fb20310c88f154a04665bd8465d138d66c665c300f61447858344_amd64, * |
| Red Hat | registry.redhat.io/discovery/discovery-ui-rhel9@sha256:2020475c1f39087c770ff031c3a4c0b384aa680b1b9a8278ad80d127420ffffc_arm64 as a component of Red Hat Discovery 2 | registry.redhat.io/discovery/discovery-ui-rhel9@sha256:2020475c1f39087c770ff031c3a4c0b384aa680b1b9a8278ad80d127420ffffc_arm64, * |
| Red Hat | registry.redhat.io/discovery/discovery-ui-rhel9@sha256:18fa5a5b82d77afe7a92e0115daf8c23df0f817d5917747d35212dc7e4c66413_amd64 as a component of Red Hat Discovery 2 | registry.redhat.io/discovery/discovery-ui-rhel9@sha256:18fa5a5b82d77afe7a92e0115daf8c23df0f817d5917747d35212dc7e4c66413_amd64, * |
| Red Hat | registry.redhat.io/discovery/discovery-server-rhel9@sha256:c517869dacaf4d3650310d4a52e83706e0b311d6ebb4a9b37b1c7acff5c142ec_arm64 as a component of Red Hat Discovery 2 | *, * |
Timeline
- Aug 6, 2025 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- Aug 2, 2026 CVE Updated
- Aug 2, 2026 Distribution Patch
- Aug 2, 2026 Security Advisory
- Aug 2, 2026 Security Advisory
- Aug 2, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/CVE-2024-12718 advisory
- https://access.redhat.com/security/cve/CVE-2025-40909 advisory
- https://access.redhat.com/security/cve/CVE-2025-4138 advisory
- https://access.redhat.com/security/cve/CVE-2025-4517 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_13267.json advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-12718 advisory
- https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f advisory
- https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a advisory
- https://github.com/python/cpython/issues/127987 advisory
- https://github.com/python/cpython/issues/135034 advisory
- https://github.com/python/cpython/pull/135037 advisory
- https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2372426 issue
- https://nvd.nist.gov/vuln/detail/CVE-2025-4138 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-4330 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2372406 issue
- https://www.cve.org/CVERecord?id=CVE-2025-6021 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2380149 issue
- https://nvd.nist.gov/vuln/detail/CVE-2025-6965 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2379274 issue
…and 43 more