Release date:
2026-09-25 10:40:33 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink
- debian/patches/CVE-2026-82049.patch: resolve the link source with
os.path.realpath() before os.link() in TarFile.makelink_with_filter(),
so a hard link whose target is a symlink no longer duplicates that
symlink inode one directory shallower, where its relative payload
re-based outside the destination and the following chmod()/utime()
hit the outside file (CWE-59).
- CVE-2026-82049
Updated packages:
-
alt-python312_3.12.14-7_amd64.deb
sha:60c7f5666d59fd9659f46a939c5b2883be5f81a1
-
alt-python312-debug_3.12.14-7_amd64.deb
sha:3de406a2de475204fc1291eaa66aa0dcc93cb155
-
alt-python312-devel_3.12.14-7_amd64.deb
sha:cdea58a211379d3e94f332ab61f266d286901810
-
alt-python312-idle_3.12.14-7_amd64.deb
sha:551aad1ff644a6960a13b9efa659da700f71b1cf
-
alt-python312-libs_3.12.14-7_amd64.deb
sha:24d4096e87dc9f36e54a5875aafa897829bbadb1
-
alt-python312-test_3.12.14-7_amd64.deb
sha:4909f75afdbf6539f04ecd96c16bf84c503522ce
-
alt-python312-tkinter_3.12.14-7_amd64.deb
sha:a270348afca94baafb45d4b4031eadf68de535ff
-
alt-python312_3.12.14-7_arm64.deb
sha:cfa471d82861c07f104aaa54f360d8dcc2a14827
-
alt-python312-debug_3.12.14-7_arm64.deb
sha:79bcb7eb86855f3d4ddc61cd3184740dd7d19967
-
alt-python312-devel_3.12.14-7_arm64.deb
sha:21421821aa6e6b859a8cb79e2a2fba49ac6bc2b9
-
alt-python312-idle_3.12.14-7_arm64.deb
sha:5ecfc91f127353565a681f644d7f394a1897488a
-
alt-python312-libs_3.12.14-7_arm64.deb
sha:1b709850a8b2adbf84ce927e161c5c4ed99c8b3c
-
alt-python312-test_3.12.14-7_arm64.deb
sha:c3d9fababa6ae1c8884e7498c906339e2c223b84
-
alt-python312-tkinter_3.12.14-7_arm64.deb
sha:df3fc435741b160e65aa35dd29b4cfa8909899e0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.