[CLSA-2026:1790187905] alt-python39: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 18:25:16 UTC
Description:
- CVE-2026-82049: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the same symlink inode materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() applied to the newly created name followed the link onto the outside file, changing its permissions and modification time and exposing its contents inside the extracted tree. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190), which resolves the hard-link source with os.path.realpath() before os.link(), plus its regression test test_sneaky_hardlink_relocation. Sufficient only in combination with CVE-2026-11940, already applied here, which blocks the no-decoy variant that never reaches os.link(); the two must not be separated.
CVEs fixed:
Updated packages:
  • alt-python39-3.9.23-28.el7.x86_64.rpm
    sha:e0e5d745fc7f2bee64ee5a8dbdea19dd01d26e31a0945ca231a1a613b86a6026
  • alt-python39-debug-3.9.23-28.el7.x86_64.rpm
    sha:af5665e089cb53491c8de8647ebd571e1bfcec44949708d624d414dbcddb8e90
  • alt-python39-devel-3.9.23-28.el7.x86_64.rpm
    sha:d64ac654232968bafb8fa64b4014859e78d468bdc2d1b3e8783987fb9bbf09dc
  • alt-python39-idle-3.9.23-28.el7.x86_64.rpm
    sha:89bf30bef0eaff50662f3addca03642b5f67f433b90a0974ee9ca4af97389b0d
  • alt-python39-libs-3.9.23-28.el7.x86_64.rpm
    sha:b54088d56cca8a1abbbc4bda8c3dff6b59fa88155943e3c68fee0a71f541f075
  • alt-python39-test-3.9.23-28.el7.x86_64.rpm
    sha:0da9bd61db1852b740e43fb115f52cd6e8f3a5edb07790f130d68c01722df14c
  • alt-python39-tkinter-3.9.23-28.el7.x86_64.rpm
    sha:fe68e551ba78c1461488a6c7db11b9fb0958d6fe4d744f8a3fe94c724973b264
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.