[CLSA-2026:1790183837] alt-python39: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 17:17:28 UTC
Description:
- CVE-2026-82049: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the same symlink inode materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() applied to the newly created name followed the link onto the outside file, changing its permissions and modification time and exposing its contents inside the extracted tree. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190), which resolves the hard-link source with os.path.realpath() before os.link(), plus its regression test test_sneaky_hardlink_relocation. Sufficient only in combination with CVE-2026-11940, already applied here, which blocks the no-decoy variant that never reaches os.link(); the two must not be separated.
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-28.el10.x86_64.rpm
    sha:43fc9e20d7d54236053f51d11344b89940e633fd88389c406f38da5f6cf2e5f4
  • alt-python39-debug-3.9.23-28.el10.x86_64.rpm
    sha:a7ca0ed902bfc63101782369c034f32d68347d0977ff7f2fb9d385fc51049034
  • alt-python39-devel-3.9.23-28.el10.x86_64.rpm
    sha:86658811aa9b314b0b58bc22e35634100faf2c8ccae62735c936afe239604ba7
  • alt-python39-idle-3.9.23-28.el10.x86_64.rpm
    sha:4e101fbaf7a9ac57db5bac133101068bf1f35e3802d4c496584b49e35d6bee5b
  • alt-python39-libs-3.9.23-28.el10.x86_64.rpm
    sha:18d50e5e3313cf2b64ff3137178980a59a0ca477e5a28d41945086e3d4a72e0e
  • alt-python39-test-3.9.23-28.el10.x86_64.rpm
    sha:74118714c83a212bfabe53d246d78177e94ded829941f77ae99882b479c82ec4
  • alt-python39-tkinter-3.9.23-28.el10.x86_64.rpm
    sha:fd23efe8bd05f6f5101e2326c5d23c3aebb6adc41e9f562a4b8e297502ccbf17
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.