Release date:
2026-09-23 17:25:16 UTC
Description:
* SECURITY UPDATE: tarfile 'data'/'tar' extraction filter bypass via a hard
link to a symbolic link (CWE-59, link following). TarFile.makelink_with_filter()
passed tarinfo._link_target straight to os.link(); link(2) does not follow
symbolic links, so an archive storing a hard link whose target is an
archived symlink got the *same symlink inode* materialised one directory
shallower than the symlink the filter had validated. Its relative body then
re-based outside the destination directory, and the chmod()/utime() that
extraction performs on the newly created name followed the link onto the
outside file, changing its permissions and modification time; its contents
also became readable through the in-tree path. Reproduced on the patched
3.8.20 tree with a four-member archive ('x' regular decoy, 'sub/'
directory, 'sub/link' -> '../x' symlink, 'escape' hard link to 'sub/link'
with mode 0777 and mtime 946684800) extracted with filter='data': a file
outside the destination went 0600 -> 0755, its mtime was rewritten to
946684800 and its contents were readable through dest/escape. After the
fix the outside file is untouched and dest/escape is a genuine in-tree hard
link to the extracted decoy.
- debian/patches/CVE-2026-82049.patch: backport of cpython
b8f23e307097552eaea2604383a12ab280520d0d (gh-157190, GH-157191,
GH-157192), which resolves the hard-link source with os.path.realpath()
before calling os.link(), plus its regression test
test_sneaky_hardlink_relocation in Lib/test/test_tarfile.py. This
one-liner is sufficient only because CVE-2026-11940 is already applied:
it closes the variant where the archive carries a decoy at the symlink's
in-destination target so os.path.exists() is true and os.link() runs,
while the no-decoy variant skips os.link() entirely and is closed by the
guard CVE-2026-11940.patch added to makelink_with_filter(). The two must
not be separated.
- CVE-2026-82049
Updated packages:
-
alt-python38_3.8.20-29_amd64.deb
sha:ed5b858a8d6c0aa373f253a733795ece0fe6aa39
-
alt-python38-debug_3.8.20-29_amd64.deb
sha:ffc28b72923776b422bf47f29cff60ef6b52a98c
-
alt-python38-devel_3.8.20-29_amd64.deb
sha:9e5307777bc3a1b1ae675989d397c1bbe25cbe9e
-
alt-python38-idle_3.8.20-29_amd64.deb
sha:1a9b3e5ce7540a11da39413bd9384e7422d5e7c2
-
alt-python38-libs_3.8.20-29_amd64.deb
sha:28e598ab87ec328830f5f244b697e1375db680a3
-
alt-python38-test_3.8.20-29_amd64.deb
sha:64dc4b7086fd90b356f5592db97bf18b5a13dd02
-
alt-python38-tkinter_3.8.20-29_amd64.deb
sha:243c41d84be40fdd9fbcc979afb3074094f44a83
-
alt-python38_3.8.20-29_arm64.deb
sha:317ec146153f098439f1b20c8f285115f9233546
-
alt-python38-debug_3.8.20-29_arm64.deb
sha:e0f344919922c3643157c27b0a8b2990fd913ce3
-
alt-python38-devel_3.8.20-29_arm64.deb
sha:416799a2dc8b2b5fd9c64ab8fabb568b5cb06fb9
-
alt-python38-idle_3.8.20-29_arm64.deb
sha:5c230ed940042c114bbd8c79a6d3c81c3ac45add
-
alt-python38-libs_3.8.20-29_arm64.deb
sha:7d4e1181e17a727a3e6904a6a91544b5c89e90e5
-
alt-python38-test_3.8.20-29_arm64.deb
sha:7dd2faa6199a218dc2e852ad4313c8ea43d551a2
-
alt-python38-tkinter_3.8.20-29_arm64.deb
sha:1003b17e84196e3e054cea7e3f13efae861f2477
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.