[CLSA-2026:1790167336] alt-python312: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-23 12:42:30 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.12.14 and blocks the no-decoy variant that never reaches os.link() under the "data" filter
Updated packages:
  • alt-python312-3.12.14-6.el10.x86_64.rpm
    sha:db9c8b41f149891119282d42e021efb5d1cf3f3b532190f8cde446348c5e7843
  • alt-python312-debug-3.12.14-6.el10.x86_64.rpm
    sha:379593319072c8cc8e7f7a64a84f85d3b37b774b70e3d48e6dd3b9c30ac77497
  • alt-python312-devel-3.12.14-6.el10.x86_64.rpm
    sha:4963ed01deb4e7532b1e6f0d2cba87ebc59d6460a487fe6ac698b9ce6c032acb
  • alt-python312-idle-3.12.14-6.el10.x86_64.rpm
    sha:6ae882b4fd578b2a35e65563cd1d2de048d0f1d89bc20dd9d88cc09fc048b105
  • alt-python312-libs-3.12.14-6.el10.x86_64.rpm
    sha:786fd21a2cac9cbe472f85eb72e178754208d48c811a558e0e1080b5211a3359
  • alt-python312-test-3.12.14-6.el10.x86_64.rpm
    sha:9c2684d3a0a18a29939ea3b308aa56aa1b5724ea6851a5012a282f861053ed2a
  • alt-python312-tkinter-3.12.14-6.el10.x86_64.rpm
    sha:b5a08cdbffe5eecbbbd4f1b282df33dd82544220fbe6817804f93d512c7d08ce
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.