Release date:
2026-09-23 13:22:40 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940.patch, which blocks the
no-decoy variant that never reaches os.link() under the "data" filter
Updated packages:
-
alt-python36-3.6.15-37.el10.x86_64.rpm
sha:641c6bdd4666ef67885defb5cccc97dfe00c6cd6e9916af4d367b87c5b32fcb9
-
alt-python36-debug-3.6.15-37.el10.x86_64.rpm
sha:b1f1871378c9ef188cbede8e77176099213c290b9d2e6b68744a36a11f52181d
-
alt-python36-devel-3.6.15-37.el10.x86_64.rpm
sha:996567ebccc2b69b8af321863e8d38a6208afe09e02955cd9a33228b2a06e8ad
-
alt-python36-libs-3.6.15-37.el10.x86_64.rpm
sha:bffb13168e54782daa1aa8caf5b8202567f22c394702a639cea4ea762dcd331e
-
alt-python36-test-3.6.15-37.el10.x86_64.rpm
sha:fbf4519ea6ccaae404e5a9ee6493a98d9f64b4aa79efe3cab24087a139f9cb02
-
alt-python36-tkinter-3.6.15-37.el10.x86_64.rpm
sha:9086ec0340628604933c2f7df6ea332cf383d3604a89e07801f6700282906fd3
-
alt-python36-tools-3.6.15-37.el10.x86_64.rpm
sha:d395cf23b4072d99e6a4ee1b77385d8862b8243399583658eec84a966d6c8209
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.