Release date:
2026-09-23 16:32:23 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940, which is native in 3.11.16
and blocks the no-decoy variant that never reaches os.link()
Updated packages:
-
alt-python311-3.11.16-2.el7.x86_64.rpm
sha:e70d03da5a13842309359eb453d5f302f8b8b5a5f81d26c35e8e84b79ea4ad89
-
alt-python311-debug-3.11.16-2.el7.x86_64.rpm
sha:1f770ba71a53688678f29c96c3167a106a5250a309f1cb67eb30eff88c8c0d9d
-
alt-python311-devel-3.11.16-2.el7.x86_64.rpm
sha:c178bccec8db7544263f8ba6dbaf14ba6fdf416d48112425fdf70f36586ed078
-
alt-python311-idle-3.11.16-2.el7.x86_64.rpm
sha:1f3748754a65b8e1fe47ab2cc756ccab0fa5c54009e9c494989af7aa93110559
-
alt-python311-libs-3.11.16-2.el7.x86_64.rpm
sha:3245797ed14ac4ccc249a15116b6987e972c106c43921eb05e3e63fb1a5beff9
-
alt-python311-test-3.11.16-2.el7.x86_64.rpm
sha:6f5b43ec64b3920b3db176f162de26691dd43460ff526f4f1f4c3ef0fe3a6865
-
alt-python311-tkinter-3.11.16-2.el7.x86_64.rpm
sha:75b4303b954e03031a1f683d9f3af7351dc450a4175def1e7d9f8f89418e3c09
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.