Release date:
2026-09-24 00:54:48 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940, which is native in 3.10.21
and blocks the no-decoy variant that never reaches os.link()
Updated packages:
-
alt-python310-3.10.21-2.el10.x86_64.rpm
sha:991a8b5f4034e78f65c5ac60a629db0983e22f1b49290142c414e02c154f45a4
-
alt-python310-debug-3.10.21-2.el10.x86_64.rpm
sha:4f2df54562ad9e0e5b286f87dbd8af92399cf4693b5a9b72dd4f6c68523a2d0b
-
alt-python310-devel-3.10.21-2.el10.x86_64.rpm
sha:40123ef6790d50f8d9a989267fa8ba2b6d15d97d1e40002bf872e6ec066d2a4f
-
alt-python310-idle-3.10.21-2.el10.x86_64.rpm
sha:e8a9bc4524807b59ec75cd1a644e3c47c29001d618cd21eaf5d280261357df6c
-
alt-python310-libs-3.10.21-2.el10.x86_64.rpm
sha:0d2e80684b6c692f64e9a4ebae0d1a478ed3562dd1dfeb80df0fb1c7a05bbe82
-
alt-python310-test-3.10.21-2.el10.x86_64.rpm
sha:e5cb26220d0341fc9c03eeb92f8fa43d3330dfae5f80d6960f1c961333a4ce61
-
alt-python310-tkinter-3.10.21-2.el10.x86_64.rpm
sha:68d8415e621a8131251202d662d5b98600b2f0d40b742e4056b1c5145f810d1e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.