[CLSA-2026:1790184304] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 17:25:16 UTC
Description:
* SECURITY UPDATE: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59, link following). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the *same symlink inode* materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() that extraction performs on the newly created name followed the link onto the outside file, changing its permissions and modification time; its contents also became readable through the in-tree path. Reproduced on the patched 3.8.20 tree with a four-member archive ('x' regular decoy, 'sub/' directory, 'sub/link' -> '../x' symlink, 'escape' hard link to 'sub/link' with mode 0777 and mtime 946684800) extracted with filter='data': a file outside the destination went 0600 -> 0755, its mtime was rewritten to 946684800 and its contents were readable through dest/escape. After the fix the outside file is untouched and dest/escape is a genuine in-tree hard link to the extracted decoy. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190, GH-157191, GH-157192), which resolves the hard-link source with os.path.realpath() before calling os.link(), plus its regression test test_sneaky_hardlink_relocation in Lib/test/test_tarfile.py. This one-liner is sufficient only because CVE-2026-11940 is already applied: it closes the variant where the archive carries a decoy at the symlink's in-destination target so os.path.exists() is true and os.link() runs, while the no-decoy variant skips os.link() entirely and is closed by the guard CVE-2026-11940.patch added to makelink_with_filter(). The two must not be separated. - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python38_3.8.20-29_amd64.deb
    sha:ed5b858a8d6c0aa373f253a733795ece0fe6aa39
  • alt-python38-debug_3.8.20-29_amd64.deb
    sha:ffc28b72923776b422bf47f29cff60ef6b52a98c
  • alt-python38-devel_3.8.20-29_amd64.deb
    sha:9e5307777bc3a1b1ae675989d397c1bbe25cbe9e
  • alt-python38-idle_3.8.20-29_amd64.deb
    sha:1a9b3e5ce7540a11da39413bd9384e7422d5e7c2
  • alt-python38-libs_3.8.20-29_amd64.deb
    sha:28e598ab87ec328830f5f244b697e1375db680a3
  • alt-python38-test_3.8.20-29_amd64.deb
    sha:64dc4b7086fd90b356f5592db97bf18b5a13dd02
  • alt-python38-tkinter_3.8.20-29_amd64.deb
    sha:243c41d84be40fdd9fbcc979afb3074094f44a83
  • alt-python38_3.8.20-29_arm64.deb
    sha:317ec146153f098439f1b20c8f285115f9233546
  • alt-python38-debug_3.8.20-29_arm64.deb
    sha:e0f344919922c3643157c27b0a8b2990fd913ce3
  • alt-python38-devel_3.8.20-29_arm64.deb
    sha:416799a2dc8b2b5fd9c64ab8fabb568b5cb06fb9
  • alt-python38-idle_3.8.20-29_arm64.deb
    sha:5c230ed940042c114bbd8c79a6d3c81c3ac45add
  • alt-python38-libs_3.8.20-29_arm64.deb
    sha:7d4e1181e17a727a3e6904a6a91544b5c89e90e5
  • alt-python38-test_3.8.20-29_arm64.deb
    sha:7dd2faa6199a218dc2e852ad4313c8ea43d551a2
  • alt-python38-tkinter_3.8.20-29_arm64.deb
    sha:1003b17e84196e3e054cea7e3f13efae861f2477
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.