[CLSA-2026:1790178886] alt-python311: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 15:54:58 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.11.16 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python311-3.11.16-2.el8.x86_64.rpm
    sha:4dbf69a4161f518feda7e68c44e90350f6f2bf91d5a1f2646a76496d3e925861
  • alt-python311-debug-3.11.16-2.el8.x86_64.rpm
    sha:81a4132dae6f9ddd4dbde4522a214d82b058ad19116227e3bf0f5ce131dce8d4
  • alt-python311-devel-3.11.16-2.el8.x86_64.rpm
    sha:dcbfda0f03bbd275dd0d818c1713961e9ae0fa55dbb6839538883c05f82dcae1
  • alt-python311-idle-3.11.16-2.el8.x86_64.rpm
    sha:f6e2ae8ebb83652181479b588f44aaeacb883ff86542f98e46564babdbcdeb09
  • alt-python311-libs-3.11.16-2.el8.x86_64.rpm
    sha:6444691486a9b76392aae71f77486903e07235200ac2cacd8a4e775aa93c202a
  • alt-python311-test-3.11.16-2.el8.x86_64.rpm
    sha:afc37e7892ec34dc1505824fffad752c38fd7df3f4a18882be08383102617145
  • alt-python311-tkinter-3.11.16-2.el8.x86_64.rpm
    sha:466c2f6205c2fd40330f70a955ca50db948aa12534295d5ecd9303bef93f4b42
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.