[CLSA-2026:1790174787] alt-python310: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 14:46:38 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.10.21 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-2.el8.x86_64.rpm
    sha:02f2a13c6764f9cf81c95ef4045c57323ea15d73dcfe46021ab64f941d30306f
  • alt-python310-debug-3.10.21-2.el8.x86_64.rpm
    sha:427f132d4fbf2e405d78c979667e0e3ad2153aa1e33e4ac37d3c4f581786deef
  • alt-python310-devel-3.10.21-2.el8.x86_64.rpm
    sha:a5278d9024af2d2274173257cc1516193e3f1b19b03360eacc391eb6d59bd3e1
  • alt-python310-idle-3.10.21-2.el8.x86_64.rpm
    sha:e6c0544d070700e6fba36a673e230797b00f842caf915b550398913aa45cfe22
  • alt-python310-libs-3.10.21-2.el8.x86_64.rpm
    sha:3ca109c550cca45a7d38791567309a774cf2145489b7a9fef8da1e0c7c717d29
  • alt-python310-test-3.10.21-2.el8.x86_64.rpm
    sha:300b987325ad7b0bc580d0a15e3a84594c948dc5080ae28d83dbca4c26911413
  • alt-python310-tkinter-3.10.21-2.el8.x86_64.rpm
    sha:cb2ff48f410bcfbb5adc8f4e1117b224a83fdb09538857fce88006d7fd6eb32e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.