python3Packages.unearth: fix CVE-2026-73030

Apply upstream path normalization and symlink target validation to prevent tar archives from writing outside the extraction directory.

6c78164e7b

Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)
This commit is contained in:
Gerhard Schwanzer
2026-08-11 17:41:33 +02:00
parent 4bef5c26a1
commit a34877a5d6

View File

@@ -32,6 +32,12 @@ buildPythonPackage rec {
hash = "sha256-t/Ubv9qC1Fvh4JsnfVgOZO/O7ZpCGHugBUt9qAjnH8c=";
excludes = [ "pdm.lock" ];
})
# Remove when updating to the first release containing this fix.
(fetchpatch {
name = "CVE-2026-73030.patch";
url = "https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3c8ba.patch";
hash = "sha256-OEf4YnpNhZcIWaFMSXQP0SA7kRV9FqKIpnkLbUrQj+4=";
})
];
build-system = [ pdm-backend ];