[CLSA-2026:1790190725] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 19:12:18 UTC
Description:
* SECURITY UPDATE: tarfile data/tar extraction filter bypassed by a hard link whose target is a symlink - debian/patches/CVE-2026-82049.patch: pass os.path.realpath() of the hard-link source to os.link() in makelink_with_filter(), so the extracted name is a hard link to the file the symlink resolves to instead of a second name for the symlink inode itself. link(2) does not follow symlinks, so without this a crafted archive could place a copy of an already-extracted symlink one directory shallower, where its relative payload re-bases outside the destination directory and the chmod/utime that follow change the mode and mtime of the outside file while exposing its contents inside the extracted tree (CWE-59). Also carries upstream's test_sneaky_hardlink_relocation regression test. This fix is effective only in combination with CVE-2026-11940, which is already part of upstream 3.11.16 and blocks the variant that never reaches os.link() - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python311_3.11.16-2_amd64.deb
    sha:ac8d2ff07503e18d07bed64f086dddc978c63534
  • alt-python311-debug_3.11.16-2_amd64.deb
    sha:19af33e02c095a95718a35ab883a0b9265b1320f
  • alt-python311-devel_3.11.16-2_amd64.deb
    sha:f40595e2af0227a66503e4db1387b4855d58fc35
  • alt-python311-idle_3.11.16-2_amd64.deb
    sha:070b9236830d91b329bed6982d9ec038ff9a4ec3
  • alt-python311-libs_3.11.16-2_amd64.deb
    sha:9c071259fd0b21ac3496afbbf9d0c0c5db19fc15
  • alt-python311-test_3.11.16-2_amd64.deb
    sha:ce971ba2c8bbecb2befdfcfc9890e4f70067a89a
  • alt-python311-tkinter_3.11.16-2_amd64.deb
    sha:9216d8e0525204c4f8becf54a05782e872e51a5e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.