[CLSA-2026:1790188169] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 18:29:42 UTC
Description:
* SECURITY UPDATE: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59, link following). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the *same symlink inode* materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() that extraction performs on the newly created name followed the link onto the outside file, changing its permissions and modification time; its contents also became readable through the in-tree path. Reproduced on the patched 3.8.20 tree with a four-member archive ('x' regular decoy, 'sub/' directory, 'sub/link' -> '../x' symlink, 'escape' hard link to 'sub/link' with mode 0777 and mtime 946684800) extracted with filter='data': a file outside the destination went 0600 -> 0755, its mtime was rewritten to 946684800 and its contents were readable through dest/escape. After the fix the outside file is untouched and dest/escape is a genuine in-tree hard link to the extracted decoy. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190, GH-157191, GH-157192), which resolves the hard-link source with os.path.realpath() before calling os.link(), plus its regression test test_sneaky_hardlink_relocation in Lib/test/test_tarfile.py. This one-liner is sufficient only because CVE-2026-11940 is already applied: it closes the variant where the archive carries a decoy at the symlink's in-destination target so os.path.exists() is true and os.link() runs, while the no-decoy variant skips os.link() entirely and is closed by the guard CVE-2026-11940.patch added to makelink_with_filter(). The two must not be separated. - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python38_3.8.20-29_amd64.deb
    sha:f78adf2e901d32451e990fe6f5b8b6dd8f71691e
  • alt-python38-debug_3.8.20-29_amd64.deb
    sha:f24f85fd98705e10ef6c83615b0e60d4e372ac3a
  • alt-python38-devel_3.8.20-29_amd64.deb
    sha:f8e94d7da0e7fe0fedca563e6239c4ae52186f22
  • alt-python38-idle_3.8.20-29_amd64.deb
    sha:e4d02e9b166c9e05d09a270934662bcf6b620452
  • alt-python38-libs_3.8.20-29_amd64.deb
    sha:756968024aada6bb01b4f51c1d64eebb4c1d00c6
  • alt-python38-test_3.8.20-29_amd64.deb
    sha:8bda96bb0b0f86911976b3cfa318669b6267664c
  • alt-python38-tkinter_3.8.20-29_amd64.deb
    sha:e614fcc602fda7582ee657086f1a66d214782678
  • alt-python38_3.8.20-29_arm64.deb
    sha:46dead77e7238cab54c750656fcc6e377b4e258e
  • alt-python38-debug_3.8.20-29_arm64.deb
    sha:b6d2a2ad10a7cdb6b1306542b9bb62e5e213ab96
  • alt-python38-devel_3.8.20-29_arm64.deb
    sha:d092f774ce0645bb0de64208dc8e41f5a56c80b8
  • alt-python38-idle_3.8.20-29_arm64.deb
    sha:e4832c1cb4853c31a03d1abbd1ceb9a85066cff0
  • alt-python38-libs_3.8.20-29_arm64.deb
    sha:0fc8812b3392edea04b896d28ce9f69062fd0427
  • alt-python38-test_3.8.20-29_arm64.deb
    sha:5a153fe202065bb6553c871cd198a26b61640817
  • alt-python38-tkinter_3.8.20-29_arm64.deb
    sha:b956d4af69f3f3e391928d3c17d960904242a206
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.