[CLSA-2026:1790184582] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 17:29:54 UTC
Description:
* SECURITY UPDATE: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59, link following). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the *same symlink inode* materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() that extraction performs on the newly created name followed the link onto the outside file, changing its permissions and modification time; its contents also became readable through the in-tree path. Reproduced on the patched 3.9.23 tree with a four-member archive ('x' regular decoy, 'sub/' directory, 'sub/link' -> '../x' symlink, 'escape' hard link to 'sub/link' with mode 0777 and mtime 946684800) extracted with filter='data': a file outside the destination went 0600 -> 0755, its mtime was rewritten to 946684800 and its contents were readable through dest/escape. After the fix the outside file is untouched and dest/escape is a genuine in-tree hard link to the extracted decoy. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190, GH-157191, GH-157192), which resolves the hard-link source with os.path.realpath() before calling os.link(), plus its regression test test_sneaky_hardlink_relocation in Lib/test/test_tarfile.py. This one-liner is sufficient only because CVE-2026-11940 is already applied: it closes the variant where the archive carries a decoy at the symlink's in-destination target so os.path.exists() is true and os.link() runs, while the no-decoy variant skips os.link() entirely and is closed by the guard CVE-2026-11940.patch added to makelink_with_filter(). The two must not be separated. - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python39_3.9.23-30_amd64.deb
    sha:f7992fbc4f59676ae52acf6a87472897358e659e
  • alt-python39-debug_3.9.23-30_amd64.deb
    sha:776ea692c0a018f87e1139973bc66055114ab6cb
  • alt-python39-devel_3.9.23-30_amd64.deb
    sha:bd818d7b3ed47398b26a35ad4cae757023424aaa
  • alt-python39-idle_3.9.23-30_amd64.deb
    sha:1c096ddeac7ad1c8e859960c66a0e0103867f7be
  • alt-python39-libs_3.9.23-30_amd64.deb
    sha:415ac497a2b6bba5d186e077ba8cc36fcac306cc
  • alt-python39-test_3.9.23-30_amd64.deb
    sha:fc3364ede5c888109056027d54711973b808f063
  • alt-python39-tkinter_3.9.23-30_amd64.deb
    sha:f567e5645105f3fdb74234fb8c84a44fb9dfcb7c
  • alt-python39_3.9.23-30_arm64.deb
    sha:e53953d381e29820d7edbfbca7cafd9727d3a13b
  • alt-python39-debug_3.9.23-30_arm64.deb
    sha:df45ae05b05c2e4db3fda8269e8757c722a51941
  • alt-python39-devel_3.9.23-30_arm64.deb
    sha:fc64082c5512100132ab7fc3001067808d7d1edf
  • alt-python39-idle_3.9.23-30_arm64.deb
    sha:087ac7b0d1a6399ad4b69b99042b3ce12310ade0
  • alt-python39-libs_3.9.23-30_arm64.deb
    sha:cc0e32a528265d2cc0b87aac233c85dc61e7ce13
  • alt-python39-test_3.9.23-30_arm64.deb
    sha:ddc319602d11a7bd8df3a4db118399f7731fe023
  • alt-python39-tkinter_3.9.23-30_arm64.deb
    sha:b047fb3adcd224c27892ee3999442bd832053532
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.