[CLSA-2026:1790181131] alt-python311: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 16:32:23 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.11.16 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python311-3.11.16-2.el7.x86_64.rpm
    sha:e70d03da5a13842309359eb453d5f302f8b8b5a5f81d26c35e8e84b79ea4ad89
  • alt-python311-debug-3.11.16-2.el7.x86_64.rpm
    sha:1f770ba71a53688678f29c96c3167a106a5250a309f1cb67eb30eff88c8c0d9d
  • alt-python311-devel-3.11.16-2.el7.x86_64.rpm
    sha:c178bccec8db7544263f8ba6dbaf14ba6fdf416d48112425fdf70f36586ed078
  • alt-python311-idle-3.11.16-2.el7.x86_64.rpm
    sha:1f3748754a65b8e1fe47ab2cc756ccab0fa5c54009e9c494989af7aa93110559
  • alt-python311-libs-3.11.16-2.el7.x86_64.rpm
    sha:3245797ed14ac4ccc249a15116b6987e972c106c43921eb05e3e63fb1a5beff9
  • alt-python311-test-3.11.16-2.el7.x86_64.rpm
    sha:6f5b43ec64b3920b3db176f162de26691dd43460ff526f4f1f4c3ef0fe3a6865
  • alt-python311-tkinter-3.11.16-2.el7.x86_64.rpm
    sha:75b4303b954e03031a1f683d9f3af7351dc450a4175def1e7d9f8f89418e3c09
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.