Release date:
2026-09-23 18:29:42 UTC
Description:
* SECURITY UPDATE: tarfile 'data'/'tar' extraction filter bypass via a hard
link to a symbolic link (CWE-59, link following). TarFile.makelink_with_filter()
passed tarinfo._link_target straight to os.link(); link(2) does not follow
symbolic links, so an archive storing a hard link whose target is an
archived symlink got the *same symlink inode* materialised one directory
shallower than the symlink the filter had validated. Its relative body then
re-based outside the destination directory, and the chmod()/utime() that
extraction performs on the newly created name followed the link onto the
outside file, changing its permissions and modification time; its contents
also became readable through the in-tree path. Reproduced on the patched
3.8.20 tree with a four-member archive ('x' regular decoy, 'sub/'
directory, 'sub/link' -> '../x' symlink, 'escape' hard link to 'sub/link'
with mode 0777 and mtime 946684800) extracted with filter='data': a file
outside the destination went 0600 -> 0755, its mtime was rewritten to
946684800 and its contents were readable through dest/escape. After the
fix the outside file is untouched and dest/escape is a genuine in-tree hard
link to the extracted decoy.
- debian/patches/CVE-2026-82049.patch: backport of cpython
b8f23e307097552eaea2604383a12ab280520d0d (gh-157190, GH-157191,
GH-157192), which resolves the hard-link source with os.path.realpath()
before calling os.link(), plus its regression test
test_sneaky_hardlink_relocation in Lib/test/test_tarfile.py. This
one-liner is sufficient only because CVE-2026-11940 is already applied:
it closes the variant where the archive carries a decoy at the symlink's
in-destination target so os.path.exists() is true and os.link() runs,
while the no-decoy variant skips os.link() entirely and is closed by the
guard CVE-2026-11940.patch added to makelink_with_filter(). The two must
not be separated.
- CVE-2026-82049
Updated packages:
-
alt-python38_3.8.20-29_amd64.deb
sha:f78adf2e901d32451e990fe6f5b8b6dd8f71691e
-
alt-python38-debug_3.8.20-29_amd64.deb
sha:f24f85fd98705e10ef6c83615b0e60d4e372ac3a
-
alt-python38-devel_3.8.20-29_amd64.deb
sha:f8e94d7da0e7fe0fedca563e6239c4ae52186f22
-
alt-python38-idle_3.8.20-29_amd64.deb
sha:e4d02e9b166c9e05d09a270934662bcf6b620452
-
alt-python38-libs_3.8.20-29_amd64.deb
sha:756968024aada6bb01b4f51c1d64eebb4c1d00c6
-
alt-python38-test_3.8.20-29_amd64.deb
sha:8bda96bb0b0f86911976b3cfa318669b6267664c
-
alt-python38-tkinter_3.8.20-29_amd64.deb
sha:e614fcc602fda7582ee657086f1a66d214782678
-
alt-python38_3.8.20-29_arm64.deb
sha:46dead77e7238cab54c750656fcc6e377b4e258e
-
alt-python38-debug_3.8.20-29_arm64.deb
sha:b6d2a2ad10a7cdb6b1306542b9bb62e5e213ab96
-
alt-python38-devel_3.8.20-29_arm64.deb
sha:d092f774ce0645bb0de64208dc8e41f5a56c80b8
-
alt-python38-idle_3.8.20-29_arm64.deb
sha:e4832c1cb4853c31a03d1abbd1ceb9a85066cff0
-
alt-python38-libs_3.8.20-29_arm64.deb
sha:0fc8812b3392edea04b896d28ce9f69062fd0427
-
alt-python38-test_3.8.20-29_arm64.deb
sha:5a153fe202065bb6553c871cd198a26b61640817
-
alt-python38-tkinter_3.8.20-29_arm64.deb
sha:b956d4af69f3f3e391928d3c17d960904242a206
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.