Release date:
2026-09-23 19:12:18 UTC
Description:
* SECURITY UPDATE: tarfile data/tar extraction filter bypassed by a hard
link whose target is a symlink
- debian/patches/CVE-2026-82049.patch: pass os.path.realpath() of the
hard-link source to os.link() in makelink_with_filter(), so the
extracted name is a hard link to the file the symlink resolves to
instead of a second name for the symlink inode itself. link(2) does
not follow symlinks, so without this a crafted archive could place a
copy of an already-extracted symlink one directory shallower, where
its relative payload re-bases outside the destination directory and
the chmod/utime that follow change the mode and mtime of the outside
file while exposing its contents inside the extracted tree (CWE-59).
Also carries upstream's test_sneaky_hardlink_relocation regression
test. This fix is effective only in combination with CVE-2026-11940,
which is already part of upstream 3.11.16 and blocks the variant that
never reaches os.link()
- CVE-2026-82049
Updated packages:
-
alt-python311_3.11.16-2_amd64.deb
sha:ac8d2ff07503e18d07bed64f086dddc978c63534
-
alt-python311-debug_3.11.16-2_amd64.deb
sha:19af33e02c095a95718a35ab883a0b9265b1320f
-
alt-python311-devel_3.11.16-2_amd64.deb
sha:f40595e2af0227a66503e4db1387b4855d58fc35
-
alt-python311-idle_3.11.16-2_amd64.deb
sha:070b9236830d91b329bed6982d9ec038ff9a4ec3
-
alt-python311-libs_3.11.16-2_amd64.deb
sha:9c071259fd0b21ac3496afbbf9d0c0c5db19fc15
-
alt-python311-test_3.11.16-2_amd64.deb
sha:ce971ba2c8bbecb2befdfcfc9890e4f70067a89a
-
alt-python311-tkinter_3.11.16-2_amd64.deb
sha:9216d8e0525204c4f8becf54a05782e872e51a5e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.