[CLSA-2026:1790168916] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 13:08:46 UTC
Description:
* SECURITY UPDATE: tarfile data/tar extraction filter bypassed by a hard link whose target is a symlink - debian/patches/CVE-2026-82049.patch: pass os.path.realpath() of the hard-link source to os.link() in makelink_with_filter(), so the extracted name is a hard link to the file the symlink resolves to instead of a second name for the symlink inode itself. link(2) does not follow symlinks, so without this a crafted archive could place a copy of an already-extracted symlink one directory shallower, where its relative payload re-bases outside the destination directory and the chmod/utime that follow change the mode and mtime of the outside file while exposing its contents inside the extracted tree (CWE-59). Also carries upstream's test_sneaky_hardlink_relocation regression test. This fix is effective only in combination with CVE-2026-11940, which is already part of upstream 3.11.16 and blocks the variant that never reaches os.link() - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python311_3.11.16-2_amd64.deb
    sha:ecdd8295e87638e8af03787432932cfa1a34ede6
  • alt-python311-debug_3.11.16-2_amd64.deb
    sha:19af33e02c095a95718a35ab883a0b9265b1320f
  • alt-python311-devel_3.11.16-2_amd64.deb
    sha:ef032b6143b3473f43d2950da0bd315060b37598
  • alt-python311-idle_3.11.16-2_amd64.deb
    sha:872203f601159d642ba52361739f8e739f5cb4c4
  • alt-python311-libs_3.11.16-2_amd64.deb
    sha:93e8231ed8054619c7295d3043f81f226f48fc4d
  • alt-python311-test_3.11.16-2_amd64.deb
    sha:a79a130ef120b8873168c3cddf12097d8870be20
  • alt-python311-tkinter_3.11.16-2_amd64.deb
    sha:48d573225ffe3adb33214d904c4dc1decb956ed4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.