[CLSA-2026:1790176881] alt-python313: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 15:21:33 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.13.15 and blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python313-3.13.15-3.el8.x86_64.rpm
    sha:63d3d3fa341d127efe85d6f716168229b3c54abeab0d7ff600834fc2af873f21
  • alt-python313-debug-3.13.15-3.el8.x86_64.rpm
    sha:d4a9ae0489991f158098eb2c4ccdba196cfd5304a129e8f6ddb8b7cf485c9e48
  • alt-python313-devel-3.13.15-3.el8.x86_64.rpm
    sha:21b078a0bd1845f0afbc23c4704cd7e40e3f2dbb7002634a95a9c027402ffa0c
  • alt-python313-idle-3.13.15-3.el8.x86_64.rpm
    sha:d6db34e7c9f2f671a166e6cf24167ff4843241ec0068dec8b9e95c5ba4ccfbe8
  • alt-python313-libs-3.13.15-3.el8.x86_64.rpm
    sha:0fe710cc59740c52e38b96c766d14dc802b98f0350f828db34a7f1273de25270
  • alt-python313-test-3.13.15-3.el8.x86_64.rpm
    sha:b40066bae8e5bdd9490d479ca51c19b4ca04e53cccf71316d02c210880b4d588
  • alt-python313-tkinter-3.13.15-3.el8.x86_64.rpm
    sha:b148adeae5cce6a2e4626e02cb496044ab108b84efed2c7479fefc6faf6a3c48
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.