Release date:
2026-09-25 10:50:07 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink
- debian/patches/CVE-2026-82049.patch: resolve the link source with
os.path.realpath() before os.link() in TarFile.makelink_with_filter(),
so a hard link whose target is a symlink no longer duplicates that
symlink inode one directory shallower, where its relative payload
re-based outside the destination and the following chmod()/utime()
hit the outside file (CWE-59).
- CVE-2026-82049
Updated packages:
-
alt-python312_3.12.14-7_amd64.deb
sha:08f90469f13c5e0723a3ee7f0c66020d7758a04f
-
alt-python312-debug_3.12.14-7_amd64.deb
sha:3de406a2de475204fc1291eaa66aa0dcc93cb155
-
alt-python312-devel_3.12.14-7_amd64.deb
sha:9172b5e54e0b98fcbd7a66e16d60f30961ec172a
-
alt-python312-idle_3.12.14-7_amd64.deb
sha:1a0213408c22f00dcfd5a2a6f0d3e34c01643f21
-
alt-python312-libs_3.12.14-7_amd64.deb
sha:a6abe7cb8e3897118266db4f76d2c6c6fb5b2486
-
alt-python312-test_3.12.14-7_amd64.deb
sha:f3c1c5cca22d6db7edf03041739f27596798c81f
-
alt-python312-tkinter_3.12.14-7_amd64.deb
sha:7381d8309d3edb052b55c8e71070129e21a05409
-
alt-python312_3.12.14-7_arm64.deb
sha:2210c13014f8a07edf2605392fdc49cd0f4d6942
-
alt-python312-debug_3.12.14-7_arm64.deb
sha:79bcb7eb86855f3d4ddc61cd3184740dd7d19967
-
alt-python312-devel_3.12.14-7_arm64.deb
sha:cf4f3d62104c7b59b88c7de2233b9a4b3fd2abb1
-
alt-python312-idle_3.12.14-7_arm64.deb
sha:a33c020978da608fe2ee499f3ff2f275174f7c24
-
alt-python312-libs_3.12.14-7_arm64.deb
sha:51c49bfa7112b0e116ef6f9e259fc2e64cdf974b
-
alt-python312-test_3.12.14-7_arm64.deb
sha:a9ee841df5e97d904901fd00c1dbe29f7bb356c0
-
alt-python312-tkinter_3.12.14-7_arm64.deb
sha:43ca98ca9427961913b8dbdfb257f6972b1826be
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.