[CLSA-2026:1790170153] alt-python38: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 13:29:23 UTC
Description:
- CVE-2026-82049: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the same symlink inode materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() applied to the newly created name followed the link onto the outside file, changing its permissions and modification time and exposing its contents inside the extracted tree. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190), which resolves the hard-link source with os.path.realpath() before os.link(), plus its regression test test_sneaky_hardlink_relocation. Sufficient only in combination with CVE-2026-11940, already applied here, which blocks the no-decoy variant that never reaches os.link(); the two must not be separated.
CVEs fixed:
Updated packages:
  • alt-python38-3.8.20-27.el8.x86_64.rpm
    sha:0002ac964fabf74cec4700b07251a9a7a123c4d98a6e24aadcabb2c975adf847
  • alt-python38-debug-3.8.20-27.el8.x86_64.rpm
    sha:8a5966eaafb250aebf3b06a205c48ce23106bc2fa29c688fa5478ad600a10322
  • alt-python38-devel-3.8.20-27.el8.x86_64.rpm
    sha:cacb2fb5689e8342c855ac48608694520623666619cfd6e64824f44b57df89a9
  • alt-python38-idle-3.8.20-27.el8.x86_64.rpm
    sha:043629ee7fadd89039b9e4080adf0a64a4ba7de4b0f2804d28912630cc9faeed
  • alt-python38-libs-3.8.20-27.el8.x86_64.rpm
    sha:1757278283c372033c432c617262e8cf54775d03a56f07757b4eea662460e538
  • alt-python38-test-3.8.20-27.el8.x86_64.rpm
    sha:104d91532e459cff3509d095b74f828f49f94a3f99437da02b2c43a4656fd9aa
  • alt-python38-tkinter-3.8.20-27.el8.x86_64.rpm
    sha:e196ceded199c9dfc31b76bc485e161dc1f8f159760a6130e772a6f54bdcaf73
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.