Release date:
2026-09-23 19:48:47 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940.patch, which blocks the
no-decoy variant that never reaches os.link() under the "data" filter
Updated packages:
-
alt-python37-3.7.17-29.el10.x86_64.rpm
sha:457f3ee4ec864a04bdb0b89bfe29ce363fb15fc8f0cf8c95310e167e78d64159
-
alt-python37-debug-3.7.17-29.el10.x86_64.rpm
sha:5c59f1ca458bffd97f0cdaba0c682b85168df7889fdddaa755f7e4353a3f8ad2
-
alt-python37-devel-3.7.17-29.el10.x86_64.rpm
sha:6cf576aa12bdf22a0f8cbf7cecf3495a5555b4de377793371cb813fb4edcf5b7
-
alt-python37-libs-3.7.17-29.el10.x86_64.rpm
sha:937c6b8dc70458c7a1dd469a9e3124df176cbde7d9e8033369f8f5efa4891439
-
alt-python37-test-3.7.17-29.el10.x86_64.rpm
sha:88712f95bad943f83c805cde629e09bf05be135d55af3f005d9eb1768b468c8c
-
alt-python37-tkinter-3.7.17-29.el10.x86_64.rpm
sha:0af00afd801638bbe79ae350db98a1201c1c95528ccccf8b7fa92a70bc53db31
-
alt-python37-tools-3.7.17-29.el10.x86_64.rpm
sha:175af25446c488ce81b18c8f77b315a283d0e127477b6e4ac576e292b6fd2750
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.