[CLSA-2026:1790175996] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 15:06:48 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink - debian/patches/CVE-2026-82049.patch: resolve the link source with os.path.realpath() before os.link() in TarFile.makelink_with_filter(), so a hard link whose target is a symlink no longer duplicates that symlink inode one directory shallower, where its relative payload re-based outside the destination and the following chmod()/utime() hit the outside file (CWE-59). - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python313_3.13.15-4_amd64.deb
    sha:f4d444f0b910c521ea2a1be99f301f7fb12b8f7a
  • alt-python313-debug_3.13.15-4_amd64.deb
    sha:620dbaafe37a1ca0c5653c4d8bc4fc35b85fe3d5
  • alt-python313-devel_3.13.15-4_amd64.deb
    sha:5ee58c8329e305a69e343d6b5a97932b0e1210f3
  • alt-python313-idle_3.13.15-4_amd64.deb
    sha:a79b50f9509e809829066ff0d135bfd659e17979
  • alt-python313-libs_3.13.15-4_amd64.deb
    sha:d0288b2d25f34036502ab347f2807d54bc4e6923
  • alt-python313-test_3.13.15-4_amd64.deb
    sha:fda8140f60e9c32a92f909f4def8b8b70e3fb172
  • alt-python313-tkinter_3.13.15-4_amd64.deb
    sha:cfa409eafe05b5ae78728b5660b040fe54bdfaab
  • alt-python313_3.13.15-4_arm64.deb
    sha:1b6251bbf0fa8bdf58762cd9c478dd7d71eb0f57
  • alt-python313-debug_3.13.15-4_arm64.deb
    sha:89c284b3dbea6b5a2326fa61dc51111d05228f45
  • alt-python313-devel_3.13.15-4_arm64.deb
    sha:48bff7459ee89e3dc9cfa863369a38f265d4812a
  • alt-python313-idle_3.13.15-4_arm64.deb
    sha:69972265817eeca24e3de093abab06dcb2576800
  • alt-python313-libs_3.13.15-4_arm64.deb
    sha:148b260822cc3436e9612d7a6052218ca1821ea9
  • alt-python313-test_3.13.15-4_arm64.deb
    sha:d07c2d066cad29c309aa3dc5b7191f53e9dcd996
  • alt-python313-tkinter_3.13.15-4_arm64.deb
    sha:4ac003680a2f56a1d93f10fcc97e6642d4a6b973
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.