Release date:
2026-09-24 00:04:41 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940.patch, which blocks the
no-decoy variant that never reaches os.link() under the "data" filter
Updated packages:
-
alt-python36-3.6.15-37.el8.x86_64.rpm
sha:253b7e12d3c22ddd15d02e4103825e8ec4354fa84f2876ab80f04037ca15be3b
-
alt-python36-debug-3.6.15-37.el8.x86_64.rpm
sha:3491403fcd07e6562c41f0e16072276a63aee5ea4280a741739f42e111c7a69a
-
alt-python36-devel-3.6.15-37.el8.x86_64.rpm
sha:dabb7d4eb79843847b20693dd6c30efc5b19370c2d806ca35b2bf8654b6934ce
-
alt-python36-libs-3.6.15-37.el8.x86_64.rpm
sha:aa4c1616fe8cf436608cae7c72c1084f9b0762ef8ef59bb70a0690121f12619a
-
alt-python36-test-3.6.15-37.el8.x86_64.rpm
sha:b99e12a102c2d377c2026600b1f090eb7923a48a7cfd8b477e2168d8fe2534b2
-
alt-python36-tkinter-3.6.15-37.el8.x86_64.rpm
sha:0118f68dc81202370c5c032446489b266310c67ba2971692788c0aafcd9ae2da
-
alt-python36-tools-3.6.15-37.el8.x86_64.rpm
sha:51d3608fadaed2bf9af1cdb17b6f27d44499fc6541145581456fe97812170ea9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.