[CLSA-2026:1790167587] alt-python310: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 12:46:39 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.10.21 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python310-3.10.21-2.el9.x86_64.rpm
    sha:2641b33c7e6e726b7004ca9feb42ee16507a70e86fe65b60dd5744e88b5bdcd7
  • alt-python310-debug-3.10.21-2.el9.x86_64.rpm
    sha:585666a91d6d975aa966df7e85fb08e7a251d4fedc3f721d6c0616d0a3635acf
  • alt-python310-devel-3.10.21-2.el9.x86_64.rpm
    sha:a606079f04bb01beef3a5d7c2eb5342a8af05551a64be9b48c0023270ab001f2
  • alt-python310-idle-3.10.21-2.el9.x86_64.rpm
    sha:e9de1f72c7b174bbcd59cfca3d854df4c2c709170c4cdd3ccb41aaf807a7399c
  • alt-python310-libs-3.10.21-2.el9.x86_64.rpm
    sha:325a6b17ab7bb39ce8ba9bedfcd5ace722948a784e4c0a06c19c1a1fe86b769d
  • alt-python310-test-3.10.21-2.el9.x86_64.rpm
    sha:1853833905f3d6be6fe2cde3ceb9664ba5c3167bcbc4a8ada6f9aa0d2ba0b853
  • alt-python310-tkinter-3.10.21-2.el9.x86_64.rpm
    sha:127bdbb1c81b77474aaaa464c61f4efec37e8a592a8d979603888406c4a0d994
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.