Release date:
2026-09-23 13:12:21 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink
- debian/patches/CVE-2026-82049.patch: resolve the link source with
os.path.realpath() before os.link() in TarFile.makelink_with_filter(),
so a hard link whose target is a symlink no longer duplicates that
symlink inode one directory shallower, where its relative payload
re-based outside the destination and the following chmod()/utime()
hit the outside file (CWE-59).
- CVE-2026-82049
Updated packages:
-
alt-python313_3.13.15-4_amd64.deb
sha:67eac594a263ed6f768a32503863d95282b83c58
-
alt-python313-debug_3.13.15-4_amd64.deb
sha:1699726b9de0c652d12ecdbebfd1ad63f2c2ef95
-
alt-python313-devel_3.13.15-4_amd64.deb
sha:275ca481ca683e0e32e2e4f77e62ff20e161b40a
-
alt-python313-idle_3.13.15-4_amd64.deb
sha:d6fa2da5dd2491efffa699fbb0c653a54dd05156
-
alt-python313-libs_3.13.15-4_amd64.deb
sha:bbf56605754adb7df98efd0b86e40fc155d07bfa
-
alt-python313-test_3.13.15-4_amd64.deb
sha:c69fdb09a464a7bc7eb9655d07675cc00a605256
-
alt-python313-tkinter_3.13.15-4_amd64.deb
sha:9cc399d4c858c1845757b8ef09c0fb60737334c6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.