[CLSA-2026:1790176243] Fix CVE(s): CVE-2026-2297, CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-25 10:23:24 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink - debian/patches/CVE-2026-82049.patch: resolve the link source with os.path.realpath() before os.link() in TarFile.makelink_with_filter(), so a hard link whose target is a symlink no longer duplicates that symlink inode one directory shallower, where its relative payload re-based outside the destination and the following chmod()/utime() hit the outside file (CWE-59). - CVE-2026-82049
Updated packages:
  • alt-python312_3.12.14-7_amd64.deb
    sha:5bc0ae1eb150498a79a00ad15c7d44d544a6a92a
  • alt-python312-debug_3.12.14-7_amd64.deb
    sha:7d1495ba517efd1a9dac6ed8fb25de6aa4b36c9e
  • alt-python312-devel_3.12.14-7_amd64.deb
    sha:baf8e5744366e021616556de26b31591fd314269
  • alt-python312-idle_3.12.14-7_amd64.deb
    sha:16593a2330daa30966e8f995124b5fcb02187f0c
  • alt-python312-libs_3.12.14-7_amd64.deb
    sha:78f2216c039177a3cad39a3383318968e881b107
  • alt-python312-test_3.12.14-7_amd64.deb
    sha:8edaa9829f9f8ae0b792e321174bd3b70425903c
  • alt-python312-tkinter_3.12.14-7_amd64.deb
    sha:95bc10010ef6a394d1d5c2326118ffd46e2969e5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.