[CLSA-2026:1790212077] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-24 01:08:09 UTC
Description:
* SECURITY UPDATE: tarfile 'data'/'tar' extraction filter bypass via a hard link to a symbolic link (CWE-59, link following). TarFile.makelink_with_filter() passed tarinfo._link_target straight to os.link(); link(2) does not follow symbolic links, so an archive storing a hard link whose target is an archived symlink got the *same symlink inode* materialised one directory shallower than the symlink the filter had validated. Its relative body then re-based outside the destination directory, and the chmod()/utime() that extraction performs on the newly created name followed the link onto the outside file, changing its permissions and modification time; its contents also became readable through the in-tree path. Reproduced on the patched 3.9.23 tree with a four-member archive ('x' regular decoy, 'sub/' directory, 'sub/link' -> '../x' symlink, 'escape' hard link to 'sub/link' with mode 0777 and mtime 946684800) extracted with filter='data': a file outside the destination went 0600 -> 0755, its mtime was rewritten to 946684800 and its contents were readable through dest/escape. After the fix the outside file is untouched and dest/escape is a genuine in-tree hard link to the extracted decoy. - debian/patches/CVE-2026-82049.patch: backport of cpython b8f23e307097552eaea2604383a12ab280520d0d (gh-157190, GH-157191, GH-157192), which resolves the hard-link source with os.path.realpath() before calling os.link(), plus its regression test test_sneaky_hardlink_relocation in Lib/test/test_tarfile.py. This one-liner is sufficient only because CVE-2026-11940 is already applied: it closes the variant where the archive carries a decoy at the symlink's in-destination target so os.path.exists() is true and os.link() runs, while the no-decoy variant skips os.link() entirely and is closed by the guard CVE-2026-11940.patch added to makelink_with_filter(). The two must not be separated. - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python39_3.9.23-30_amd64.deb
    sha:fdf9aa525bbaa9a209edf567167c0208d630a07c
  • alt-python39-debug_3.9.23-30_amd64.deb
    sha:776ea692c0a018f87e1139973bc66055114ab6cb
  • alt-python39-devel_3.9.23-30_amd64.deb
    sha:a50974ecb4e43e70112c7a4b875577b65e662fa3
  • alt-python39-idle_3.9.23-30_amd64.deb
    sha:381834b635f78bf0d6fca89f8bebcd0dd6da80dc
  • alt-python39-libs_3.9.23-30_amd64.deb
    sha:bdef65275d389950031059a515a15e4de3aaba03
  • alt-python39-test_3.9.23-30_amd64.deb
    sha:1abde7d74b89d7b8a060b0a519df20ff7ece9d84
  • alt-python39-tkinter_3.9.23-30_amd64.deb
    sha:48f7220833a8a090461f90fed3543b6e394be74d
  • alt-python39_3.9.23-30_arm64.deb
    sha:7139d5558403ec438e15ce31449b97c05dec8409
  • alt-python39-debug_3.9.23-30_arm64.deb
    sha:df45ae05b05c2e4db3fda8269e8757c722a51941
  • alt-python39-devel_3.9.23-30_arm64.deb
    sha:e19bbfb757d940397ccb44bb94d2d1b534a74b0c
  • alt-python39-idle_3.9.23-30_arm64.deb
    sha:3ca04113fe39a0a8af3e334dfb695ad68b3a937f
  • alt-python39-libs_3.9.23-30_arm64.deb
    sha:40389b33e9fe4ba22b23baa062d0a463c6c32118
  • alt-python39-test_3.9.23-30_arm64.deb
    sha:edc8d3593c3c3aa3230321e6cb0b678f4dc0896a
  • alt-python39-tkinter_3.9.23-30_arm64.deb
    sha:0f9d94fb3b0b5da7702ea78a287bca506152cb65
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.