Release date:
2026-09-23 18:41:48 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940, which is native in 3.12.14
and blocks the no-decoy variant that never reaches os.link() under the
"data" filter
Updated packages:
-
alt-python312-3.12.14-6.el8.x86_64.rpm
sha:ede8037b400f244a4162a7d7cd135089133e7f0c123345db60278cba0bdc38e8
-
alt-python312-debug-3.12.14-6.el8.x86_64.rpm
sha:d22f225e228b9a00ed614faa13f064196cb2ed027dcd7e8771d81cd9a7bccec9
-
alt-python312-devel-3.12.14-6.el8.x86_64.rpm
sha:fd8262a27294fec49f2e493661324b95af9e7fd71524a2814e81d58c2bea443b
-
alt-python312-idle-3.12.14-6.el8.x86_64.rpm
sha:d915360194df738d2b5572e8ab77201747ea6729aa2309d8e4228c8e95898587
-
alt-python312-libs-3.12.14-6.el8.x86_64.rpm
sha:9a888ca24cf4931142cd23b57fa0d6d498a082b53187eaca207f2b29df3c6042
-
alt-python312-test-3.12.14-6.el8.x86_64.rpm
sha:6fde43594076560dbab10fa8d99c52344cf83d6935abb86fe6f7dae95cc6b7c7
-
alt-python312-tkinter-3.12.14-6.el8.x86_64.rpm
sha:e6acca8462e892a30d359f6d405e3f2fa537e7300801f8ad177f58ba4c3b8803
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.