[CLSA-2026:1790208271] alt-python36: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-24 00:04:41 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940.patch, which blocks the no-decoy variant that never reaches os.link() under the "data" filter
CVEs fixed:
Updated packages:
  • alt-python36-3.6.15-37.el8.x86_64.rpm
    sha:253b7e12d3c22ddd15d02e4103825e8ec4354fa84f2876ab80f04037ca15be3b
  • alt-python36-debug-3.6.15-37.el8.x86_64.rpm
    sha:3491403fcd07e6562c41f0e16072276a63aee5ea4280a741739f42e111c7a69a
  • alt-python36-devel-3.6.15-37.el8.x86_64.rpm
    sha:dabb7d4eb79843847b20693dd6c30efc5b19370c2d806ca35b2bf8654b6934ce
  • alt-python36-libs-3.6.15-37.el8.x86_64.rpm
    sha:aa4c1616fe8cf436608cae7c72c1084f9b0762ef8ef59bb70a0690121f12619a
  • alt-python36-test-3.6.15-37.el8.x86_64.rpm
    sha:b99e12a102c2d377c2026600b1f090eb7923a48a7cfd8b477e2168d8fe2534b2
  • alt-python36-tkinter-3.6.15-37.el8.x86_64.rpm
    sha:0118f68dc81202370c5c032446489b266310c67ba2971692788c0aafcd9ae2da
  • alt-python36-tools-3.6.15-37.el8.x86_64.rpm
    sha:51d3608fadaed2bf9af1cdb17b6f27d44499fc6541145581456fe97812170ea9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.