Release date:
2026-09-23 15:06:48 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink
- debian/patches/CVE-2026-82049.patch: resolve the link source with
os.path.realpath() before os.link() in TarFile.makelink_with_filter(),
so a hard link whose target is a symlink no longer duplicates that
symlink inode one directory shallower, where its relative payload
re-based outside the destination and the following chmod()/utime()
hit the outside file (CWE-59).
- CVE-2026-82049
Updated packages:
-
alt-python313_3.13.15-4_amd64.deb
sha:f4d444f0b910c521ea2a1be99f301f7fb12b8f7a
-
alt-python313-debug_3.13.15-4_amd64.deb
sha:620dbaafe37a1ca0c5653c4d8bc4fc35b85fe3d5
-
alt-python313-devel_3.13.15-4_amd64.deb
sha:5ee58c8329e305a69e343d6b5a97932b0e1210f3
-
alt-python313-idle_3.13.15-4_amd64.deb
sha:a79b50f9509e809829066ff0d135bfd659e17979
-
alt-python313-libs_3.13.15-4_amd64.deb
sha:d0288b2d25f34036502ab347f2807d54bc4e6923
-
alt-python313-test_3.13.15-4_amd64.deb
sha:fda8140f60e9c32a92f909f4def8b8b70e3fb172
-
alt-python313-tkinter_3.13.15-4_amd64.deb
sha:cfa409eafe05b5ae78728b5660b040fe54bdfaab
-
alt-python313_3.13.15-4_arm64.deb
sha:1b6251bbf0fa8bdf58762cd9c478dd7d71eb0f57
-
alt-python313-debug_3.13.15-4_arm64.deb
sha:89c284b3dbea6b5a2326fa61dc51111d05228f45
-
alt-python313-devel_3.13.15-4_arm64.deb
sha:48bff7459ee89e3dc9cfa863369a38f265d4812a
-
alt-python313-idle_3.13.15-4_arm64.deb
sha:69972265817eeca24e3de093abab06dcb2576800
-
alt-python313-libs_3.13.15-4_arm64.deb
sha:148b260822cc3436e9612d7a6052218ca1821ea9
-
alt-python313-test_3.13.15-4_arm64.deb
sha:d07c2d066cad29c309aa3dc5b7191f53e9dcd996
-
alt-python313-tkinter_3.13.15-4_arm64.deb
sha:4ac003680a2f56a1d93f10fcc97e6642d4a6b973
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.