[CLSA-2026:1790213974] Fix CVE(s): CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-24 01:39:45 UTC
Description:
* SECURITY UPDATE: tarfile data/tar filter bypass via a hard link to a symlink - debian/patches/CVE-2026-82049.patch: resolve the link source with os.path.realpath() before os.link() in TarFile.makelink_with_filter(), so a hard link whose target is a symlink no longer duplicates that symlink inode one directory shallower, where its relative payload re-based outside the destination and the following chmod()/utime() hit the outside file (CWE-59). - CVE-2026-82049
CVEs fixed:
Updated packages:
  • alt-python313_3.13.15-4_amd64.deb
    sha:1d79387c4a62e8873126040c4c7183377ddadc52
  • alt-python313-debug_3.13.15-4_amd64.deb
    sha:620dbaafe37a1ca0c5653c4d8bc4fc35b85fe3d5
  • alt-python313-devel_3.13.15-4_amd64.deb
    sha:fc5baedf07a40d8cf0de945f5c5df9e8050a1e01
  • alt-python313-idle_3.13.15-4_amd64.deb
    sha:64588f9a32722fbb2a2f4bd5cbdd5aaeceb92943
  • alt-python313-libs_3.13.15-4_amd64.deb
    sha:48e92d37cf3b77c9b63ccf38880b47a4db6542d6
  • alt-python313-test_3.13.15-4_amd64.deb
    sha:d703d622a1b5d9362ee1ba081be6558cbca23b69
  • alt-python313-tkinter_3.13.15-4_amd64.deb
    sha:9d2a377c695fc38ba51b671c53454ae6ff6db35b
  • alt-python313_3.13.15-4_arm64.deb
    sha:b7f07a90de15ce0e2c45ff167650ca7a56b87590
  • alt-python313-debug_3.13.15-4_arm64.deb
    sha:89c284b3dbea6b5a2326fa61dc51111d05228f45
  • alt-python313-devel_3.13.15-4_arm64.deb
    sha:7dbea6a12cc8b3bf12876704b616f7d23da154f1
  • alt-python313-idle_3.13.15-4_arm64.deb
    sha:bb0a6a28c9dbc960b270497137094ea8fcc0b906
  • alt-python313-libs_3.13.15-4_arm64.deb
    sha:f17c41ef58a0414025572c6f68ac4c705d23fe65
  • alt-python313-test_3.13.15-4_arm64.deb
    sha:6c187b19684b65bf0fcd30fa1024389d5a81d13a
  • alt-python313-tkinter_3.13.15-4_arm64.deb
    sha:344718702cae2f9487c939f2adc0803a1c08b697
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.