Release date:
2026-09-23 12:42:30 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940, which is native in 3.12.14
and blocks the no-decoy variant that never reaches os.link() under the
"data" filter
Updated packages:
-
alt-python312-3.12.14-6.el10.x86_64.rpm
sha:db9c8b41f149891119282d42e021efb5d1cf3f3b532190f8cde446348c5e7843
-
alt-python312-debug-3.12.14-6.el10.x86_64.rpm
sha:379593319072c8cc8e7f7a64a84f85d3b37b774b70e3d48e6dd3b9c30ac77497
-
alt-python312-devel-3.12.14-6.el10.x86_64.rpm
sha:4963ed01deb4e7532b1e6f0d2cba87ebc59d6460a487fe6ac698b9ce6c032acb
-
alt-python312-idle-3.12.14-6.el10.x86_64.rpm
sha:6ae882b4fd578b2a35e65563cd1d2de048d0f1d89bc20dd9d88cc09fc048b105
-
alt-python312-libs-3.12.14-6.el10.x86_64.rpm
sha:786fd21a2cac9cbe472f85eb72e178754208d48c811a558e0e1080b5211a3359
-
alt-python312-test-3.12.14-6.el10.x86_64.rpm
sha:9c2684d3a0a18a29939ea3b308aa56aa1b5724ea6851a5012a282f861053ed2a
-
alt-python312-tkinter-3.12.14-6.el10.x86_64.rpm
sha:b5a08cdbffe5eecbbbd4f1b282df33dd82544220fbe6817804f93d512c7d08ce
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.