[CLSA-2026:1790212915] Fix CVE(s): CVE-2026-2297, CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-25 10:20:24 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink - debian/patches/CVE-2026-82049.patch: resolve the link source with os.path.realpath() before os.link() in TarFile.makelink_with_filter(), so a hard link whose target is a symlink no longer duplicates that symlink inode one directory shallower, where its relative payload re-based outside the destination and the following chmod()/utime() hit the outside file (CWE-59). - CVE-2026-82049
Updated packages:
  • alt-python312_3.12.14-7_amd64.deb
    sha:b05d8ee6db73188d96999ff2a35ff991b5199a08
  • alt-python312-debug_3.12.14-7_amd64.deb
    sha:7d1495ba517efd1a9dac6ed8fb25de6aa4b36c9e
  • alt-python312-devel_3.12.14-7_amd64.deb
    sha:47fad46b696dc9042c3c8935738956164b6f5d45
  • alt-python312-idle_3.12.14-7_amd64.deb
    sha:077bd68a5c5cb0ed2b6752675cd3bf2afe33fa6c
  • alt-python312-libs_3.12.14-7_amd64.deb
    sha:06a2f87aab9ddebcfb391fec728ad088559e3f1a
  • alt-python312-test_3.12.14-7_amd64.deb
    sha:8325220d2f05dd7a97841ee91950bce76438375f
  • alt-python312-tkinter_3.12.14-7_amd64.deb
    sha:c2b9a1a402467b6ba4409649d90f97dcc4b7c541
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.