[CLSA-2026:1790181356] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 16:36:08 UTC
Description:
* SECURITY UPDATE: tarfile data/tar extraction filter bypassed by a hard link whose target is a symlink - debian/patches/CVE-2026-82049.patch: pass os.path.realpath() of the hard-link source to os.link() in makelink_with_filter(), so the extracted name is a hard link to the file the symlink resolves to instead of a second name for the symlink inode itself. link(2) does not follow symlinks, so without this a crafted archive could place a copy of an already-extracted symlink one directory shallower, where its relative payload re-bases outside the destination directory and the chmod/utime that follow change the mode and mtime of the outside file while exposing its contents inside the extracted tree (CWE-59). Also carries upstream's test_sneaky_hardlink_relocation regression test. This fix is effective only in combination with CVE-2026-11940, which is already part of upstream 3.10.21 and blocks the variant that never reaches os.link() - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python310_3.10.21-2_amd64.deb
    sha:b5528325ea8a751a726d4cdf76cec04654007ff4
  • alt-python310-debug_3.10.21-2_amd64.deb
    sha:ea9b482905c0ff2cf47b5ed91a6fe30f13f76822
  • alt-python310-devel_3.10.21-2_amd64.deb
    sha:607f12af14d9f73ca9ff9e96acd4310a69b04ebe
  • alt-python310-idle_3.10.21-2_amd64.deb
    sha:4df34a17b066881f8b63df9fb53527accde8e36d
  • alt-python310-libs_3.10.21-2_amd64.deb
    sha:d4f360d4dbcdf6c512a005f13247f97956726cba
  • alt-python310-test_3.10.21-2_amd64.deb
    sha:bf7f57f6e7ff3815126e19f0fdf3c030b44e3224
  • alt-python310-tkinter_3.10.21-2_amd64.deb
    sha:b683c400e8eec819ae9eb060d318785b650e2503
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.