[CLSA-2026:1790175514] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 14:58:45 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink - debian/patches/CVE-2026-82049.patch: resolve the link source with os.path.realpath() before os.link() in TarFile.makelink_with_filter(), so a hard link whose target is a symlink no longer duplicates that symlink inode one directory shallower, where its relative payload re-based outside the destination and the following chmod()/utime() hit the outside file (CWE-59). - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python313_3.13.15-4_amd64.deb
    sha:f2aee21b2f5cf1aecde256b66ce92ceb473907f2
  • alt-python313-debug_3.13.15-4_amd64.deb
    sha:1699726b9de0c652d12ecdbebfd1ad63f2c2ef95
  • alt-python313-devel_3.13.15-4_amd64.deb
    sha:5d6ef325b0a3f25ae71fb52c5f70701ed51ba0a8
  • alt-python313-idle_3.13.15-4_amd64.deb
    sha:85d498451258bb13114b863300f8eb6e5569fd18
  • alt-python313-libs_3.13.15-4_amd64.deb
    sha:e5f5b2edb7aeaef0c423de8a33335a06e026b30a
  • alt-python313-test_3.13.15-4_amd64.deb
    sha:7ed01e28ceaec8fe5b4ef245b4eba792501adc01
  • alt-python313-tkinter_3.13.15-4_amd64.deb
    sha:c21ac36b595fa102794e2b406fe89cff92d5af35
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.