[CLSA-2026:1790211277] alt-python310: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-24 00:54:48 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.10.21 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-2.el10.x86_64.rpm
    sha:991a8b5f4034e78f65c5ac60a629db0983e22f1b49290142c414e02c154f45a4
  • alt-python310-debug-3.10.21-2.el10.x86_64.rpm
    sha:4f2df54562ad9e0e5b286f87dbd8af92399cf4693b5a9b72dd4f6c68523a2d0b
  • alt-python310-devel-3.10.21-2.el10.x86_64.rpm
    sha:40123ef6790d50f8d9a989267fa8ba2b6d15d97d1e40002bf872e6ec066d2a4f
  • alt-python310-idle-3.10.21-2.el10.x86_64.rpm
    sha:e8a9bc4524807b59ec75cd1a644e3c47c29001d618cd21eaf5d280261357df6c
  • alt-python310-libs-3.10.21-2.el10.x86_64.rpm
    sha:0d2e80684b6c692f64e9a4ebae0d1a478ed3562dd1dfeb80df0fb1c7a05bbe82
  • alt-python310-test-3.10.21-2.el10.x86_64.rpm
    sha:e5cb26220d0341fc9c03eeb92f8fa43d3330dfae5f80d6960f1c961333a4ce61
  • alt-python310-tkinter-3.10.21-2.el10.x86_64.rpm
    sha:68d8415e621a8131251202d662d5b98600b2f0d40b742e4056b1c5145f810d1e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.