Release date:
2026-09-23 16:36:08 UTC
Description:
* SECURITY UPDATE: tarfile data/tar extraction filter bypassed by a hard
link whose target is a symlink
- debian/patches/CVE-2026-82049.patch: pass os.path.realpath() of the
hard-link source to os.link() in makelink_with_filter(), so the
extracted name is a hard link to the file the symlink resolves to
instead of a second name for the symlink inode itself. link(2) does
not follow symlinks, so without this a crafted archive could place a
copy of an already-extracted symlink one directory shallower, where
its relative payload re-bases outside the destination directory and
the chmod/utime that follow change the mode and mtime of the outside
file while exposing its contents inside the extracted tree (CWE-59).
Also carries upstream's test_sneaky_hardlink_relocation regression
test. This fix is effective only in combination with CVE-2026-11940,
which is already part of upstream 3.10.21 and blocks the variant that
never reaches os.link()
- CVE-2026-82049
Updated packages:
-
alt-python310_3.10.21-2_amd64.deb
sha:b5528325ea8a751a726d4cdf76cec04654007ff4
-
alt-python310-debug_3.10.21-2_amd64.deb
sha:ea9b482905c0ff2cf47b5ed91a6fe30f13f76822
-
alt-python310-devel_3.10.21-2_amd64.deb
sha:607f12af14d9f73ca9ff9e96acd4310a69b04ebe
-
alt-python310-idle_3.10.21-2_amd64.deb
sha:4df34a17b066881f8b63df9fb53527accde8e36d
-
alt-python310-libs_3.10.21-2_amd64.deb
sha:d4f360d4dbcdf6c512a005f13247f97956726cba
-
alt-python310-test_3.10.21-2_amd64.deb
sha:bf7f57f6e7ff3815126e19f0fdf3c030b44e3224
-
alt-python310-tkinter_3.10.21-2_amd64.deb
sha:b683c400e8eec819ae9eb060d318785b650e2503
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.