Release date:
2026-09-23 14:46:38 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940, which is native in 3.10.21
and blocks the no-decoy variant that never reaches os.link()
Updated packages:
-
alt-python310-3.10.21-2.el8.x86_64.rpm
sha:02f2a13c6764f9cf81c95ef4045c57323ea15d73dcfe46021ab64f941d30306f
-
alt-python310-debug-3.10.21-2.el8.x86_64.rpm
sha:427f132d4fbf2e405d78c979667e0e3ad2153aa1e33e4ac37d3c4f581786deef
-
alt-python310-devel-3.10.21-2.el8.x86_64.rpm
sha:a5278d9024af2d2274173257cc1516193e3f1b19b03360eacc391eb6d59bd3e1
-
alt-python310-idle-3.10.21-2.el8.x86_64.rpm
sha:e6c0544d070700e6fba36a673e230797b00f842caf915b550398913aa45cfe22
-
alt-python310-libs-3.10.21-2.el8.x86_64.rpm
sha:3ca109c550cca45a7d38791567309a774cf2145489b7a9fef8da1e0c7c717d29
-
alt-python310-test-3.10.21-2.el8.x86_64.rpm
sha:300b987325ad7b0bc580d0a15e3a84594c948dc5080ae28d83dbca4c26911413
-
alt-python310-tkinter-3.10.21-2.el8.x86_64.rpm
sha:cb2ff48f410bcfbb5adc8f4e1117b224a83fdb09538857fce88006d7fd6eb32e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.