[CLSA-2026:1790191871] alt-python36: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 19:31:23 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940.patch, which blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python36-3.6.15-37.el7.x86_64.rpm
    sha:28a469b51087651fbf5ee5869aff9b6f4cc96116a9a304b7bd7d41896fc02385
  • alt-python36-debug-3.6.15-37.el7.x86_64.rpm
    sha:372baa3161f8cc175652373f63ea0a82b177e0a487250c730e654234caf69094
  • alt-python36-devel-3.6.15-37.el7.x86_64.rpm
    sha:c8f4a64725736d154c61329ca9a8abb2c92a5d93168806b30c5cfbf03f8f6f42
  • alt-python36-libs-3.6.15-37.el7.x86_64.rpm
    sha:0f086c7ee73596eeaacf0d2fcfdb0070051b4d51e9d9d14c71c68cec2d2eea37
  • alt-python36-test-3.6.15-37.el7.x86_64.rpm
    sha:7e1f20652e49be7bf84464722385ca46c23c03e5ab06dc9e73ee240f4598d40d
  • alt-python36-tkinter-3.6.15-37.el7.x86_64.rpm
    sha:bf2e9daa2632fb249fe820ffde11bf344f877028bf67f23257d84f071825582e
  • alt-python36-tools-3.6.15-37.el7.x86_64.rpm
    sha:de7fea9490d72d3749e26434fac80b59f538f7569e3b13022830cdb1b064df63
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.