Release date:
2026-09-24 01:54:43 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940.patch, which blocks the
no-decoy variant that never reaches os.link() under the "data" filter
Updated packages:
-
alt-python37-3.7.17-29.el7.x86_64.rpm
sha:c640d5fd55ba94c8565ded5c6137a0ca9dc0d329020d41e7839c571a176d4d0d
-
alt-python37-debug-3.7.17-29.el7.x86_64.rpm
sha:07a52699dea0c3c9f61a7331ead7c6f40e334d5dab2d96cdd60f220df2d2bd90
-
alt-python37-devel-3.7.17-29.el7.x86_64.rpm
sha:304cc3b688b015a1444155fa4a4c750e2c6f704102a7b31a7d99138d799edb0c
-
alt-python37-libs-3.7.17-29.el7.x86_64.rpm
sha:d7156d0bc36ed39ed560831a61ed5a5a2d7c125d029458d57a1e72ff0e0fca42
-
alt-python37-test-3.7.17-29.el7.x86_64.rpm
sha:855f645f34c21cff329ef147419dc4a5b53bd57d26115336737e04727e93eba4
-
alt-python37-tkinter-3.7.17-29.el7.x86_64.rpm
sha:99e6cdbbbaa18f9a8c7cf8f30314a717bea9f260c90af9023472e27a37d3c90b
-
alt-python37-tools-3.7.17-29.el7.x86_64.rpm
sha:f92b5de117f3f587b8c9c56fdf1fdb709a2013b9e8d7fdc796e6a083a64eb21a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.