Release date:
2026-09-25 10:20:24 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink
- debian/patches/CVE-2026-82049.patch: resolve the link source with
os.path.realpath() before os.link() in TarFile.makelink_with_filter(),
so a hard link whose target is a symlink no longer duplicates that
symlink inode one directory shallower, where its relative payload
re-based outside the destination and the following chmod()/utime()
hit the outside file (CWE-59).
- CVE-2026-82049
Updated packages:
-
alt-python312_3.12.14-7_amd64.deb
sha:b05d8ee6db73188d96999ff2a35ff991b5199a08
-
alt-python312-debug_3.12.14-7_amd64.deb
sha:7d1495ba517efd1a9dac6ed8fb25de6aa4b36c9e
-
alt-python312-devel_3.12.14-7_amd64.deb
sha:47fad46b696dc9042c3c8935738956164b6f5d45
-
alt-python312-idle_3.12.14-7_amd64.deb
sha:077bd68a5c5cb0ed2b6752675cd3bf2afe33fa6c
-
alt-python312-libs_3.12.14-7_amd64.deb
sha:06a2f87aab9ddebcfb391fec728ad088559e3f1a
-
alt-python312-test_3.12.14-7_amd64.deb
sha:8325220d2f05dd7a97841ee91950bce76438375f
-
alt-python312-tkinter_3.12.14-7_amd64.deb
sha:c2b9a1a402467b6ba4409649d90f97dcc4b7c541
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.