[CLSA-2026:1790192915] alt-python37: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 19:48:47 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940.patch, which blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python37-3.7.17-29.el10.x86_64.rpm
    sha:457f3ee4ec864a04bdb0b89bfe29ce363fb15fc8f0cf8c95310e167e78d64159
  • alt-python37-debug-3.7.17-29.el10.x86_64.rpm
    sha:5c59f1ca458bffd97f0cdaba0c682b85168df7889fdddaa755f7e4353a3f8ad2
  • alt-python37-devel-3.7.17-29.el10.x86_64.rpm
    sha:6cf576aa12bdf22a0f8cbf7cecf3495a5555b4de377793371cb813fb4edcf5b7
  • alt-python37-libs-3.7.17-29.el10.x86_64.rpm
    sha:937c6b8dc70458c7a1dd469a9e3124df176cbde7d9e8033369f8f5efa4891439
  • alt-python37-test-3.7.17-29.el10.x86_64.rpm
    sha:88712f95bad943f83c805cde629e09bf05be135d55af3f005d9eb1768b468c8c
  • alt-python37-tkinter-3.7.17-29.el10.x86_64.rpm
    sha:0af00afd801638bbe79ae350db98a1201c1c95528ccccf8b7fa92a70bc53db31
  • alt-python37-tools-3.7.17-29.el10.x86_64.rpm
    sha:175af25446c488ce81b18c8f77b315a283d0e127477b6e4ac576e292b6fd2750
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.