Release date:
2026-09-23 13:08:46 UTC
Description:
* SECURITY UPDATE: tarfile data/tar extraction filter bypassed by a hard
link whose target is a symlink
- debian/patches/CVE-2026-82049.patch: pass os.path.realpath() of the
hard-link source to os.link() in makelink_with_filter(), so the
extracted name is a hard link to the file the symlink resolves to
instead of a second name for the symlink inode itself. link(2) does
not follow symlinks, so without this a crafted archive could place a
copy of an already-extracted symlink one directory shallower, where
its relative payload re-bases outside the destination directory and
the chmod/utime that follow change the mode and mtime of the outside
file while exposing its contents inside the extracted tree (CWE-59).
Also carries upstream's test_sneaky_hardlink_relocation regression
test. This fix is effective only in combination with CVE-2026-11940,
which is already part of upstream 3.11.16 and blocks the variant that
never reaches os.link()
- CVE-2026-82049
Updated packages:
-
alt-python311_3.11.16-2_amd64.deb
sha:ecdd8295e87638e8af03787432932cfa1a34ede6
-
alt-python311-debug_3.11.16-2_amd64.deb
sha:19af33e02c095a95718a35ab883a0b9265b1320f
-
alt-python311-devel_3.11.16-2_amd64.deb
sha:ef032b6143b3473f43d2950da0bd315060b37598
-
alt-python311-idle_3.11.16-2_amd64.deb
sha:872203f601159d642ba52361739f8e739f5cb4c4
-
alt-python311-libs_3.11.16-2_amd64.deb
sha:93e8231ed8054619c7295d3043f81f226f48fc4d
-
alt-python311-test_3.11.16-2_amd64.deb
sha:a79a130ef120b8873168c3cddf12097d8870be20
-
alt-python311-tkinter_3.11.16-2_amd64.deb
sha:48d573225ffe3adb33214d904c4dc1decb956ed4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.