Release date:
2026-09-24 01:39:45 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink
- debian/patches/CVE-2026-82049.patch: resolve the link source with
os.path.realpath() before os.link() in TarFile.makelink_with_filter(),
so a hard link whose target is a symlink no longer duplicates that
symlink inode one directory shallower, where its relative payload
re-based outside the destination and the following chmod()/utime()
hit the outside file (CWE-59).
- CVE-2026-82049
Updated packages:
-
alt-python313_3.13.15-4_amd64.deb
sha:1d79387c4a62e8873126040c4c7183377ddadc52
-
alt-python313-debug_3.13.15-4_amd64.deb
sha:620dbaafe37a1ca0c5653c4d8bc4fc35b85fe3d5
-
alt-python313-devel_3.13.15-4_amd64.deb
sha:fc5baedf07a40d8cf0de945f5c5df9e8050a1e01
-
alt-python313-idle_3.13.15-4_amd64.deb
sha:64588f9a32722fbb2a2f4bd5cbdd5aaeceb92943
-
alt-python313-libs_3.13.15-4_amd64.deb
sha:48e92d37cf3b77c9b63ccf38880b47a4db6542d6
-
alt-python313-test_3.13.15-4_amd64.deb
sha:d703d622a1b5d9362ee1ba081be6558cbca23b69
-
alt-python313-tkinter_3.13.15-4_amd64.deb
sha:9d2a377c695fc38ba51b671c53454ae6ff6db35b
-
alt-python313_3.13.15-4_arm64.deb
sha:b7f07a90de15ce0e2c45ff167650ca7a56b87590
-
alt-python313-debug_3.13.15-4_arm64.deb
sha:89c284b3dbea6b5a2326fa61dc51111d05228f45
-
alt-python313-devel_3.13.15-4_arm64.deb
sha:7dbea6a12cc8b3bf12876704b616f7d23da154f1
-
alt-python313-idle_3.13.15-4_arm64.deb
sha:bb0a6a28c9dbc960b270497137094ea8fcc0b906
-
alt-python313-libs_3.13.15-4_arm64.deb
sha:f17c41ef58a0414025572c6f68ac4c705d23fe65
-
alt-python313-test_3.13.15-4_arm64.deb
sha:6c187b19684b65bf0fcd30fa1024389d5a81d13a
-
alt-python313-tkinter_3.13.15-4_arm64.deb
sha:344718702cae2f9487c939f2adc0803a1c08b697
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.