Release date:
2026-09-23 19:52:31 UTC
Description:
- CVE-2026-82049: tarfile 'data'/'tar' extraction filter bypass via a hard link to a
symbolic link (CWE-59). TarFile.makelink_with_filter() passed
tarinfo._link_target straight to os.link(); link(2) does not follow symbolic
links, so an archive storing a hard link whose target is an archived symlink
got the same symlink inode materialised one directory shallower than the
symlink the filter had validated. Its relative body then re-based outside the
destination directory, and the chmod()/utime() applied to the newly created
name followed the link onto the outside file, changing its permissions and
modification time and exposing its contents inside the extracted tree.
- debian/patches/CVE-2026-82049.patch: backport of cpython
b8f23e307097552eaea2604383a12ab280520d0d (gh-157190), which resolves the
hard-link source with os.path.realpath() before os.link(), plus its
regression test test_sneaky_hardlink_relocation. Sufficient only in
combination with CVE-2026-11940, already applied here, which blocks the
no-decoy variant that never reaches os.link(); the two must not be separated.
Updated packages:
-
alt-python39-3.9.23-28.el9.x86_64.rpm
sha:671cefbda6c3faa56ed5192854a4ee7353e751df8213a553d53492445397f2d6
-
alt-python39-debug-3.9.23-28.el9.x86_64.rpm
sha:b0155774516246c909c50ff8841797dfd48a9b90c8db39de51dff1179608a821
-
alt-python39-devel-3.9.23-28.el9.x86_64.rpm
sha:e80873af286cfa60376cb94b17d3de1cee7a886b8abb31fa24831f637d7fec0b
-
alt-python39-idle-3.9.23-28.el9.x86_64.rpm
sha:68720c9c0c684428bbba2f23bcd44acb2ecb93e8ab490569ed172f8ddfcbc953
-
alt-python39-libs-3.9.23-28.el9.x86_64.rpm
sha:57746e5746e7d64283b747f995c15acd89ed426de282f8110cb7a14367422f29
-
alt-python39-test-3.9.23-28.el9.x86_64.rpm
sha:e7c87ec89afa20b82c0dc7cd56bfaafda3cebc2b4b56ca493b99c4c3a81f0ad2
-
alt-python39-tkinter-3.9.23-28.el9.x86_64.rpm
sha:576139dfc0e67bac20e47f63cfebf1e89b8c413731d2f2eabbab466d3ef0b9c3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.