Release date:
2026-09-23 19:08:17 UTC
Description:
* SECURITY UPDATE: tarfile data/tar extraction filter bypassed by a hard
link whose target is a symlink
- debian/patches/CVE-2026-82049.patch: pass os.path.realpath() of the
hard-link source to os.link() in makelink_with_filter(), so the
extracted name is a hard link to the file the symlink resolves to
instead of a second name for the symlink inode itself. link(2) does
not follow symlinks, so without this a crafted archive could place a
copy of an already-extracted symlink one directory shallower, where
its relative payload re-bases outside the destination directory and
the chmod/utime that follow change the mode and mtime of the outside
file while exposing its contents inside the extracted tree (CWE-59).
Also carries upstream's test_sneaky_hardlink_relocation regression
test. This fix is effective only in combination with CVE-2026-11940,
which is already part of upstream 3.10.21 and blocks the variant that
never reaches os.link()
- CVE-2026-82049
Updated packages:
-
alt-python310_3.10.21-2_amd64.deb
sha:65d7025fd5649208caa7b89182b98e24784ce48e
-
alt-python310-debug_3.10.21-2_amd64.deb
sha:ea9b482905c0ff2cf47b5ed91a6fe30f13f76822
-
alt-python310-devel_3.10.21-2_amd64.deb
sha:b6e0f6f7319b81eb9cf62aae234046d758ecc380
-
alt-python310-idle_3.10.21-2_amd64.deb
sha:bddc85515bd2becc4b9730281513413b349bd0d2
-
alt-python310-libs_3.10.21-2_amd64.deb
sha:cf4d8846c6922e2d37d8250cee18bd769b4a4ec3
-
alt-python310-test_3.10.21-2_amd64.deb
sha:134db76657acf239c017738100063500669d4ac7
-
alt-python310-tkinter_3.10.21-2_amd64.deb
sha:074c9ecbdd4ea2a0b627e395bce0c8283cb55008
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.