[CLSA-2026:1790167807] alt-python311: Fix of CVE-2026-82049
Type:
security
Severity:
Important
Release date:
2026-09-23 12:50:20 UTC
Description:
- CVE-2026-82049: resolve the hard-link source before os.link() in tarfile's makelink_with_filter(), so a crafted archive whose hard link targets a just-extracted symlink can no longer duplicate that symlink inode one directory shallower, where its relative payload re-bases outside the destination and the following chmod/utime act on the outside file (CWE-59). Carries upstream's test_sneaky_hardlink_relocation. Effective only together with CVE-2026-11940, which is native in 3.11.16 and blocks the no-decoy variant that never reaches os.link()
CVEs fixed:
Updated packages:
  • alt-python311-3.11.16-2.el10.x86_64.rpm
    sha:b1fbcb3ef3672e13cd20d6c3eb6663dbe43790f7a91bd72ae5eb8ca60fc45a29
  • alt-python311-debug-3.11.16-2.el10.x86_64.rpm
    sha:5725daa44687b32b2838c6258fe156c21296b645a6d374adf1f57a28843cad35
  • alt-python311-devel-3.11.16-2.el10.x86_64.rpm
    sha:497bf5ca4172b4828708032a82ba96cea0f59f9e7beccb7a25084d7aaeecebd2
  • alt-python311-idle-3.11.16-2.el10.x86_64.rpm
    sha:f3d26fde7382c635d61f80c61034ab9bd47fd6ab0c54a285e2cd4935fb270a63
  • alt-python311-libs-3.11.16-2.el10.x86_64.rpm
    sha:89cae9710c85fc38ba4f5d2887cab911dca513d0f732fe5ca647d39cea7608da
  • alt-python311-test-3.11.16-2.el10.x86_64.rpm
    sha:90247136493cef599b3d283efae7c7312eba961b6744ea64c0a5d25137ae8fa2
  • alt-python311-tkinter-3.11.16-2.el10.x86_64.rpm
    sha:5bed42699cf2a9314944b5833790fad957c220512bc3046d5b908819f2233267
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.