Release date:
2026-09-23 15:48:28 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in
tarfile's makelink_with_filter(), so a crafted archive whose hard link
targets a just-extracted symlink can no longer duplicate that symlink
inode one directory shallower, where its relative payload re-bases
outside the destination and the following chmod/utime act on the
outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation.
Effective only together with CVE-2026-11940.patch, which blocks the
no-decoy variant that never reaches os.link() under the "data" filter
Updated packages:
-
alt-python36-3.6.15-37.el9.x86_64.rpm
sha:ffaad38e529cb1a30fc9752104086f40e1b68beb44b2bf69a6436bf579dd8d1a
-
alt-python36-debug-3.6.15-37.el9.x86_64.rpm
sha:eb495754b6820ad31759cdcdc83b39f5e847020d1c6d5569fd63e6b56a7c8ee1
-
alt-python36-devel-3.6.15-37.el9.x86_64.rpm
sha:3af5278a035f23611a7199bb46965f254bd2c7ccd97e9cb4172e81d10bea2531
-
alt-python36-libs-3.6.15-37.el9.x86_64.rpm
sha:dd232c187bdf714b22a8fda4cd1b8838caae786a38552b251f69817e2548df74
-
alt-python36-test-3.6.15-37.el9.x86_64.rpm
sha:0f2af1c3d15b462d112f49ded7cd0108fe607b7ffab362bb515690a2d476c32c
-
alt-python36-tkinter-3.6.15-37.el9.x86_64.rpm
sha:da62bcaff6100a7a470a19d00676941dacfe18393b3defbf36160e60da812bc3
-
alt-python36-tools-3.6.15-37.el9.x86_64.rpm
sha:6a2e6c2617ba903db66d2991262dea2b99548c110e68e92ff7bfebc057e75e4d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.